Bug 154330

Summary: Get avc errors generated from depmod.
Product: [Fedora] Fedora Reporter: sangu <sangu.fedora>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED RAWHIDE QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhide   
Target Milestone: ---   
Target Release: ---   
Hardware: i386   
OS: Linux   
Whiteboard:
Fixed In Version: selinux-policy-targeted-1.23.10-5 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2005-04-15 07:47:37 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description sangu 2005-04-10 05:01:45 UTC
Description of problem:
$rpm -e kernel-module-nvidia-2.6.11-1.1231_FC4

in demsg
[...]
audit(1113108813.976:0): avc:  denied  { unlink } for  pid=4576 exe=/sbin/depmod
name=modules.dep dev=hda8 ino=746 scontext=root:system_r:depmod_t
tcontext=root:object_r:modules_object_t tclass=file


Version-Release number of selected component (if applicable):
selinux-policy-targeted-1.23.8-2

How reproducible:
always

Additional info:
$ls -laZ /sbin/depmod
-rwxr-xr-x  root     root     system_u:object_r:depmod_exec_t  /sbin/depmod