selinux issue with wine

Przemek Klosowski przemek.klosowski at nist.gov
Thu Jul 29 21:50:25 UTC 2010


Ankur Sinha reported a SELinux message about an unsafe memory access in 
Wine.

On 07/28/2010 07:46 AM, Frank Murphy wrote:
> Instead it tells you using this program can be a risk (dangerous?)
> But if you really need this program:
> su
> /usr/sbin/setsebool -P mmap_low_allowed 1

Does that enable this access pattern for every program ran by Wine,
or for just the one he tried?

The real question here is 'is it in general safe to enable this'.
Since Wine is that it is running multiple programs, it may be
a bad idea to tell SELinux it's OK, unless people agree that there are 
no serious security consequences. I am not sure, and I haven't enabled 
it on my system.

Please feel free to redirect this away from Fedora devel list.


More information about the devel mailing list