Bug 172394
Summary: | avc denied message for makedev with pcmcia modem | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Orion Poplawski <orion> |
Component: | selinux-policy-targeted | Assignee: | Russell Coker <rcoker> |
Status: | CLOSED NOTABUG | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 4 | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2005-12-08 21:01:43 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Orion Poplawski
2005-11-03 18:51:53 UTC
The portmap messages seem unrelated, but I'm seeing on other systems as well: Nov 10 08:52:25 makani kernel: audit(1131637933.908:3): avc: denied { read } for pid=2308 comm="portmap" name="nsswitch.conf" dev=hda5 ino=289813 scontext=system_u:system_r:portmap_t tcontext=system_u:object_r:etc_runtime_t tclass=file Did some program/script create the /etc/nsswitch.conf file It should have a file context of etc_t on it. restorecon /etc/nsswitch.conf should fix. I would disable cardmgr transition to make it work. setsebool -P cardmgr_disable_trans=1 Cardmgr needs to run MAKEDEV and MAKEDEV is too powerfull, so it doesn't make sense to muck around with the policy and cardmgr is going away in FC5. /etc/nsswitch.conf is installed by cfengine. Looks like it got set back to etc_t at some point. I edited the file, let cfengine replace and stayed at etc_t. Perhaps a relic from some other config? Thanks for the cargmgr boolean. |