execmem

Ulrich Drepper drepper at redhat.com
Wed Jan 11 22:26:16 UTC 2006


Jason Dravet wrote:
> It works, but my audit.log is full of:
> type=AVC msg=audit(1137011293.241:40): avc:  granted  { execmem } for 
> pid=2260 comm="firefox-bin"


firefox (or C++ code using symbol visibility in general) has problems
introduced by the compiler:

https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=175442


This is a hard problem.  Until then the policy indeed relaxes the
situation for firefox, thunderbird, etc

-- 
➧ Ulrich Drepper ➧ Red Hat, Inc. ➧ 444 Castro St ➧ Mountain View, CA ❖

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 251 bytes
Desc: OpenPGP digital signature
Url : http://lists.fedoraproject.org/pipermail/selinux/attachments/20060111/b3f39b4e/attachment.bin 


More information about the selinux mailing list