Warning: subject /sbin/gradm_pam vs /etc/localtime symlink

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

Warning: subject /sbin/gradm_pam vs /etc/localtime symlink

Postby Dwokfur » Tue Dec 24, 2013 9:23 pm

I'm in the process of systemd transition. It seems to be feasible so far. mtab is now a symlink.
I've also upgraded /etc/localtime to be a symlink.
Now I got this warning upon loading the policy:
Warning: object does not exist in role root, subject /sbin/gradm_pam for the target of the symlink object /etc/localtime specified on line X of /etc/grsec/policy.
Line X is the line where role root is defined in the policy.
I have no gradm_pam installed on the system, nor it is mentioned in the policy. /etc/localtime is also not specified in the policy. If I specify the non-existent gradm_pam for role root, the warning stays the same.
I guess I can ignore it, but I'm curious about the proper resolution of the warning.
I had no time to upgrade the system lately since I'm busy with systemd transition.

Merry Christmas to all Grsec & PAX developers:
Dw.
Dwokfur
 
Posts: 99
Joined: Tue Jun 08, 2004 10:07 am

Re: Warning: subject /sbin/gradm_pam vs /etc/localtime symli

Postby spender » Wed Dec 25, 2013 4:24 pm

Hi,

The gradm_pam subject is auto-added from gradm_adm.c, you'll need to modify the source to eliminate the warning. What is /etc/localtime now a symlink to?

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm

Re: Warning: subject /sbin/gradm_pam vs /etc/localtime symli

Postby Dwokfur » Wed Dec 25, 2013 7:40 pm

/etc/localtime points to /usr/share/zoneinfo/Europe/Budapest
Thx: Dw.
Dwokfur
 
Posts: 99
Joined: Tue Jun 08, 2004 10:07 am


Return to grsecurity support