Bug 1047958

Summary: New avc for mythtv
Product: [Fedora] Fedora Reporter: David Highley <david.m.highley>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 20CC: dominick.grift, dwalsh, lvrabec, mgrepl
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-3.12.1-116.fc20 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-01-16 07:12:27 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description David Highley 2014-01-02 17:45:15 UTC
Description of problem:
New avc for mythtv

Version-Release number of selected component (if applicable):
selinux-policy-3.12.1-106.fc20.noarch
mythtv-common-0.27-3.fc20.x86_64

How reproducible:


Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.120:11058): arch=c000003e syscall=257 success=no exit=-13 a0=ffffffffffffff9c a1=3354d7a67c a2=90800 a3=0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.120:11058): avc:  denied  { read } for  pid=2477 comm="mythweb.pl" name="cpu" dev="sysfs" ino=37 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=dir
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.200:11059): arch=c000003e syscall=2 success=no exit=-13 a0=7f011aaff4f2 a1=80000 a2=1b6 a3=7fff8b638db0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.200:11059): avc:  denied  { read } for  pid=2477 comm="mythweb.pl" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.203:11060): arch=c000003e syscall=109 success=no exit=-13 a0=0 a1=0 a2=100 a3=0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.203:11060): avc:  denied  { setpgid } for  pid=2477 comm="mythweb.pl" scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:system_r:httpd_mythtv_script_t:s0 tclass=process
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.210:11061): arch=c000003e syscall=2 success=no exit=-13 a0=7f90e12fb4f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2477 pid=2482 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="sh" exe="/usr/bin/bash" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.210:11061): avc:  denied  { read } for  pid=2482 comm="sh" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.211:11062): arch=c000003e syscall=2 success=no exit=-13 a0=7f78a3c894f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2477 pid=2483 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="sh" exe="/usr/bin/bash" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.211:11062): avc:  denied  { read } for  pid=2483 comm="sh" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Thu Jan  2 07:11:16 2014
type=SYSCALL msg=audit(1388675476.941:11063): arch=c000003e syscall=2 success=no exit=-13 a0=7f9623e9a4f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2483 pid=2485 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="ffmpeg" exe="/usr/bin/ffmpeg" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null)
type=AVC msg=audit(1388675476.941:11063): avc:  denied  { read } for  pid=2485 comm="ffmpeg" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file

Comment 1 Daniel Walsh 2014-01-02 22:25:51 UTC
0bedea3ea57dbc1c03b85dacbae12256ffb1954e fixes this in git.

Comment 2 Lukas Vrabec 2014-01-04 00:32:06 UTC
back ported to F20 and F19.

Comment 3 Fedora Update System 2014-01-13 22:57:51 UTC
selinux-policy-3.12.1-116.fc20 has been submitted as an update for Fedora 20.
https://admin.fedoraproject.org/updates/selinux-policy-3.12.1-116.fc20

Comment 4 Fedora Update System 2014-01-15 05:59:25 UTC
Package selinux-policy-3.12.1-116.fc20:
* should fix your issue,
* was pushed to the Fedora 20 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.12.1-116.fc20'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2014-0806/selinux-policy-3.12.1-116.fc20
then log in and leave karma (feedback).

Comment 5 Fedora Update System 2014-01-16 07:12:27 UTC
selinux-policy-3.12.1-116.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.