Gradm policy errors/ warnings
Posted: Sat Sep 07, 2013 2:42 pm
e allowed to be enabled.
gradm -E
Write access is allowed by role root to /sys, the directory which holds entries that allow modifying kernel variables.
Warning: object does not exist in role colin, subject /usr/share/software-center/update-software-center-agent for the target of the symlink object /proc/mounts specified on line 6394 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/software-center/software-center-dbus for the target of the symlink object /proc/mounts specified on line 6316 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/oneconf/oneconf-service for the target of the symlink object /proc/mounts specified on line 6165 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/apport/apport-gtk for the target of the symlink object /proc/mounts specified on line 6084 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/x86_64-linux-gnu/unity-lens-video/unity-video-lens-daemon for the target of the symlink object /etc/alternatives/updatedb specified on line 5990 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/x86_64-linux-gnu/unity-lens-video/unity-video-lens-daemon for the target of the symlink object /etc/alternatives/locate specified on line 5989 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/unity-lens-photos/unity-lens-photos for the target of the symlink object /proc/mounts specified on line 5376 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/sda2/subsystem specified on line 4883 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /sys/dev/block/8:2 specified on line 4882 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /proc/mounts specified on line 4874 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/nautilus for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/sda2/subsystem specified on line 4014 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/nautilus for the target of the symlink object /sys/dev/block/8:2 specified on line 4013 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/indicator-cpufreq for the target of the symlink object /proc/mounts specified on line 3900 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/sbin/alsactl for the target of the symlink object /root/.config/pulse/2a7c9e4458ccbfd5a964c1c0520b0164-runtime specified on line 2700 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/sbin/aa-logprof for the target of the symlink object /proc/mounts specified on line 2642 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/bin/indicator-cpufreq-selector for the target of the symlink object /proc/mounts specified on line 1906 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/bin/gedit for the target of the symlink object /proc/mounts specified on line 1842 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/udevadm for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/subsystem specified on line 1594 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/udevadm for the target of the symlink object /sys/dev/block/8:0 specified on line 1593 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/plymouthd for the target of the symlink object /sys/devices/pci0000:00/0000:00:01.0/0000:01:00.0/driver specified on line 1444 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/apparmor_parser for the target of the symlink object /proc/mounts specified on line 1137 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/resolvconf/update.d/libc for the target of the symlink object /etc/resolv.conf specified on line 1007 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /var/lock specified on line 943 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /lib64/ld-linux-x86-64.so.2 specified on line 899 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /dev/shm specified on line 874 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /bin/dash for the target of the symlink object /proc/mounts specified on line 363 of /etc/grsec/policy.
Warning: object does not exist in role colord, subject /usr/lib/colord/colord for the target of the symlink object /proc/mounts specified on line 86 of /etc/grsec/policy.
There were 1 holes found in your RBAC configuration. These must be fixed before the RBAC system will be allowed to be enabled.
http://pastebin.com/JmvqVDnH
Running 3.10 kernel, Ubuntu desktop. I don't want to break anything or screw it up and have to restart, so if there's any quick advice let me know.
gradm -E
Write access is allowed by role root to /sys, the directory which holds entries that allow modifying kernel variables.
Warning: object does not exist in role colin, subject /usr/share/software-center/update-software-center-agent for the target of the symlink object /proc/mounts specified on line 6394 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/software-center/software-center-dbus for the target of the symlink object /proc/mounts specified on line 6316 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/oneconf/oneconf-service for the target of the symlink object /proc/mounts specified on line 6165 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/share/apport/apport-gtk for the target of the symlink object /proc/mounts specified on line 6084 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/x86_64-linux-gnu/unity-lens-video/unity-video-lens-daemon for the target of the symlink object /etc/alternatives/updatedb specified on line 5990 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/x86_64-linux-gnu/unity-lens-video/unity-video-lens-daemon for the target of the symlink object /etc/alternatives/locate specified on line 5989 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/unity-lens-photos/unity-lens-photos for the target of the symlink object /proc/mounts specified on line 5376 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/sda2/subsystem specified on line 4883 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /sys/dev/block/8:2 specified on line 4882 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/lib/gvfs/gvfs-udisks2-volume-monitor for the target of the symlink object /proc/mounts specified on line 4874 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/nautilus for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/sda2/subsystem specified on line 4014 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/nautilus for the target of the symlink object /sys/dev/block/8:2 specified on line 4013 of /etc/grsec/policy.
Warning: object does not exist in role colin, subject /usr/bin/indicator-cpufreq for the target of the symlink object /proc/mounts specified on line 3900 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/sbin/alsactl for the target of the symlink object /root/.config/pulse/2a7c9e4458ccbfd5a964c1c0520b0164-runtime specified on line 2700 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/sbin/aa-logprof for the target of the symlink object /proc/mounts specified on line 2642 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/bin/indicator-cpufreq-selector for the target of the symlink object /proc/mounts specified on line 1906 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /usr/bin/gedit for the target of the symlink object /proc/mounts specified on line 1842 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/udevadm for the target of the symlink object /sys/devices/pci0000:00/0000:00:1f.2/ata1/host0/target0:0:0/0:0:0:0/block/sda/subsystem specified on line 1594 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/udevadm for the target of the symlink object /sys/dev/block/8:0 specified on line 1593 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/plymouthd for the target of the symlink object /sys/devices/pci0000:00/0000:00:01.0/0000:01:00.0/driver specified on line 1444 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /sbin/apparmor_parser for the target of the symlink object /proc/mounts specified on line 1137 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/resolvconf/update.d/libc for the target of the symlink object /etc/resolv.conf specified on line 1007 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /var/lock specified on line 943 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /lib64/ld-linux-x86-64.so.2 specified on line 899 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /etc/init.d for the target of the symlink object /dev/shm specified on line 874 of /etc/grsec/policy.
Warning: object does not exist in role root, subject /bin/dash for the target of the symlink object /proc/mounts specified on line 363 of /etc/grsec/policy.
Warning: object does not exist in role colord, subject /usr/lib/colord/colord for the target of the symlink object /proc/mounts specified on line 86 of /etc/grsec/policy.
There were 1 holes found in your RBAC configuration. These must be fixed before the RBAC system will be allowed to be enabled.
http://pastebin.com/JmvqVDnH
Running 3.10 kernel, Ubuntu desktop. I don't want to break anything or screw it up and have to restart, so if there's any quick advice let me know.