Sunday, November 14th, 2010, 10:08 am
SELinux: Friend or Foe?
few days ago I started working with Fedora 14. So far, so good, at least as far as the desktop machine goes (a laptop is another story and Kubuntu runs fine on another desktop). Something has just happened in Fedora which never happened to me before. Kate (an editor) got stuck and its memory (RAM) consumption went up through the roof to over 1.5 GB, so obviously it froze the system for a while. The process needed to be forcibly killed.
Now, it’s not entirely clear what happened there (maybe a program bug), but this is unusual and it looks bad for Fedora or for KDE (or the combination in Fedora 14 KDE spin). What did happen is that SELinux came up with an error implying that it stood in Kate’s way and maybe it’s partly responsible for this type of behaviour. It yielded the following error, implying that it was trying to help when in fact it seemed like it only stood in the way.
Summary:
SELinux is preventing /usr/bin/kate (deleted) “mmap_zero” access on <Unknown>.
Detailed Description:
SELinux denied access requested by kate. The current boolean settings do not
allow this access. If you have not setup kate to require this access this may
signal an intrusion attempt. If you do intend this access you need to change the
booleans on this system to allow the access.Allowing Access:
Confined processes can be configured to run requiring different access, SELinux
provides booleans to allow you to turn on/off access as needed. The boolean
mmap_low_allowed is set incorrectly.
Boolean Description:
Control the ability to mmap a low area of the address space, as configured by
/proc/sys/kernel/mmap_min_addr.Fix Command:
# setsebool -P mmap_low_allowed 1
Additional Information:
Source Context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1
023
Target Context unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1
023
Target Objects None [ memprotect ]
Source kate
Source Path /usr/bin/kate (deleted)
Port <Unknown>
Host blueberry
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.9.7-3.fc14
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Plugin Name catchall_boolean
Host Name blueberry
Platform Linux blueberry 2.6.35.6-45.fc14.i686 #1 SMP Mon
Oct 18 23:56:17 UTC 2010 i686 i686
Alert Count 112
First Seen Sun 14 Nov 2010 09:35:01 AM GMT
Last Seen Sun 14 Nov 2010 09:35:17 AM GMT
Local ID 4d9759c9-e672-475d-bf61-151d1688909a
Line NumbersRaw Audit Messages
node=blueberry type=AVC msg=audit(1289727317.378:856): avc: denied { mmap_zero } for pid=1880 comm=”kate” scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=memprotect
node=blueberry type=SYSCALL msg=audit(1289727317.378:856): arch=40000003 syscall=192 success=no exit=-13 a0=0 a1=100000 a2=0 a3=4022 items=0 ppid=1629 pid=1880 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 tty=(none) ses=1 comm=”kate” exe=2F7573722F62696E2F6B617465202864656C6574656429 subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null)
For years I’ve been working with no data loss, but this time I had to revert back to a previously-saved version of a document I worked on and then rewrite bits of it. Perhaps I had enough confidence in the system to only hit save (CTRL+S) once in a very long time. This experience has taught me to save my work more often but more importantly it showed that Fedora can act rather bizarrely where Kubuntu never did. As a result of this behaviour I was unable to save my work. SELinux implies there was an “attack” on the system, but obviously there was not.






Filed under: 
HIS is the sixth episode, which has just been recorded by Tim and Roy. This was done right after today’s testing of Fedora and Fusion 14. I installed it permanently on 2 boxes, whereas Tim tried Fusion on his side and, as usual, his site OpenBytes has some show notes. As we’ve both had a chance to test it on some machines, we may also post detailed reviews soon (c.f. [cref 41364 our first show], which was a Fedora 14 special that covered Fusion too).

intend to publish a long overview of Web resources for tagged data. In the mean time, based on the excellent Web page of 
udden change in plans and improvement of research direction leads me to the exploration of MRI tagging, which proves to be difficult when one tries to actually find raw data to work with, not information about it. In the coming days I plan to prepare a post explaining to people where they can obtain tagged data of the brain and the heart (trying to help others solve the problem which occupies many hours of my time). The Internet is extremely mature when it comes to sharing of text and sometimes even audio and film, copyright being an obvious barrier. When it comes to medical data, however, it is another story altogether, even if it’s totally anonymised. Personally, I’ve put 3-D scans of my brain on this Web site, hoping to provide people with the sort of data I sometimes struggle to get a hold of.
This show closes with a lovely song from