Re: Help Needed Identifying a File and a Security Failure on it.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 24/12/22 12:28, Samuel Sieb wrote:
On 12/23/22 17:27, Samuel Sieb wrote:
On 12/23/22 15:33, Stephen Morris wrote:
Hi,
     How do I identify what file .#user-1000@7668ca11a5184a26bcf4a7c1858f9574-0000000000000a42-0005ef6078e3e7f0.journalc7d37931ac52343c is? The component before the "@" in the file name looks like the file may be relative to my userid. I'm using an F37 system upgraded from F36.      Also how do I determine why "journal-offline" would be denied "relabelfrom" access on that file by selinux?      I have given journal-offline the access attempted (I know this might be problematic given the questions I'm asking), but I'm also trying to determine why it happened in the first place, and whether or not, as indicated in the error details, I should be raising this as a bug. The timing of this error seems to be indicating it occurred during boot this morning, and the audit message is indicating the file is potentially on device "sdd1", which is potentially my fedora root partition, which doesn't have /boot nor /boot/efi as they are on another device, and if it is the root device, that device is a btrfs logical device and both the physical and logical devices have the same label.

That looks like a temporary file of some sort.  It would most likely be in /var/log/journal/<some kind of id>/.

The id is the value from /etc/machine-id.
I've just checked /var/log/journal/<some kind of id>/ on a freshly warm booted system, and the user file listed above is still there albeit without the .# prefix and without the suffix after journal, so having given journal the relabelfrom access, it now looks to me like it is trying to rename the above file to remove the prefix and suffix, which it now can do (I'm only surmising that is what is happening as I don't understand what the message meant). If that is what is happening why does journal-offline not have the access by default and should it be reported? There is a similarly named file in the folder with "system" before the "@", which presumably journal-offline has no issues with, so why should it have issues with the files created for the logging in user?

regards,
Steve

_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue
_______________________________________________
users mailing list -- users@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to users-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/users@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue



[Index of Archives]     [Older Fedora Users]     [Fedora Announce]     [Fedora Package Announce]     [EPEL Announce]     [EPEL Devel]     [Fedora Magazine]     [Fedora Summer Coding]     [Fedora Laptop]     [Fedora Cloud]     [Fedora Advisory Board]     [Fedora Education]     [Fedora Security]     [Fedora Scitech]     [Fedora Robotics]     [Fedora Infrastructure]     [Fedora Websites]     [Anaconda Devel]     [Fedora Devel Java]     [Fedora Desktop]     [Fedora Fonts]     [Fedora Marketing]     [Fedora Management Tools]     [Fedora Mentors]     [Fedora Package Review]     [Fedora R Devel]     [Fedora PHP Devel]     [Kickstart]     [Fedora Music]     [Fedora Packaging]     [Fedora SELinux]     [Fedora Legal]     [Fedora Kernel]     [Fedora OCaml]     [Coolkey]     [Virtualization Tools]     [ET Management Tools]     [Yum Users]     [Yosemite News]     [Gnome Users]     [KDE Users]     [Fedora Art]     [Fedora Docs]     [Fedora Sparc]     [Libvirt Users]     [Fedora ARM]

  Powered by Linux