Page 1 of 1

Warning: subject /sbin/gradm_pam vs /etc/localtime symlink

PostPosted: Tue Dec 24, 2013 9:23 pm
by Dwokfur
I'm in the process of systemd transition. It seems to be feasible so far. mtab is now a symlink.
I've also upgraded /etc/localtime to be a symlink.
Now I got this warning upon loading the policy:
Warning: object does not exist in role root, subject /sbin/gradm_pam for the target of the symlink object /etc/localtime specified on line X of /etc/grsec/policy.
Line X is the line where role root is defined in the policy.
I have no gradm_pam installed on the system, nor it is mentioned in the policy. /etc/localtime is also not specified in the policy. If I specify the non-existent gradm_pam for role root, the warning stays the same.
I guess I can ignore it, but I'm curious about the proper resolution of the warning.
I had no time to upgrade the system lately since I'm busy with systemd transition.

Merry Christmas to all Grsec & PAX developers:
Dw.

Re: Warning: subject /sbin/gradm_pam vs /etc/localtime symli

PostPosted: Wed Dec 25, 2013 4:24 pm
by spender
Hi,

The gradm_pam subject is auto-added from gradm_adm.c, you'll need to modify the source to eliminate the warning. What is /etc/localtime now a symlink to?

-Brad

Re: Warning: subject /sbin/gradm_pam vs /etc/localtime symli

PostPosted: Wed Dec 25, 2013 7:40 pm
by Dwokfur
/etc/localtime points to /usr/share/zoneinfo/Europe/Budapest
Thx: Dw.