Bug 179402

Summary: denial messages during boot
Product: [Fedora] Fedora Reporter: Orion Poplawski <orion>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhide   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-01-31 15:02:27 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Orion Poplawski 2006-01-31 00:04:45 UTC
Description of problem:
Up to date rawhide.  Here's what dmesg has:

audit(1138664777.683:2): avc:  denied  { search } for  pid=1384
comm="pam_console_app" name="var" dev=hda8 ino=1269217
scontext=system_u:system_r:pam_console_t:s0-s0:c0.c255
tcontext=system_u:object_r:file_t:s0 tclass=dir

audit(1138664803.444:78): avc:  denied  { read write } for  pid=1590 comm="sadc"
name="0" dev=devpts ino=2 scontext=system_u:system_r:sysstat_t:s0
tcontext=system_u:object_r:devpts_t:s0 tclass=chr_file

audit(1138664804.344:80): avc:  denied  { dac_override } for  pid=1600
comm="readahead" capability=1 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:system_r:readahead_t:s0 tclass=capability
audit(1138664804.344:81): avc:  denied  { dac_read_search } for  pid=1600
comm="readahead" capability=2 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:system_r:readahead_t:s0 tclass=capability
audit(1138664805.168:84): avc:  denied  { read } for  pid=1600 comm="readahead"
name="display" dev=ramfs ino=4373 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:object_r:ramfs_t:s0 tclass=file
audit(1138664805.168:85): avc:  denied  { read } for  pid=1600 comm="readahead"
name="rhgb-console" dev=ramfs ino=4436 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:object_r:ramfs_t:s0 tclass=fifo_file

audit(1138664815.697:90): avc:  denied  { read write } for  pid=2021
comm="hid2hci" name="001" dev=tmpfs ino=4081
scontext=system_u:system_r:bluetooth_t:s0 tcontext=system_u:object_r:device_t:s0
tclass=chr_file
audit(1138664815.697:91): avc:  denied  { read } for  pid=2021 comm="hid2hci"
name="001" dev=tmpfs ino=4081 scontext=system_u:system_r:bluetooth_t:s0
tcontext=system_u:object_r:device_t:s0 tclass=chr_file

audit(1138664835.206:96): avc:  denied  { getattr } for  pid=2719
comm="avahi-daemon" name="localtime" dev=hda8 ino=1042113
scontext=system_u:system_r:avahi_t:s0
tcontext=system_u:object_r:etc_runtime_t:s0 tclass=file
audit(1138664835.206:97): avc:  denied  { read } for  pid=2719
comm="avahi-daemon" name="localtime" dev=hda8 ino=1042113
scontext=system_u:system_r:avahi_t:s0
tcontext=system_u:object_r:etc_runtime_t:s0 tclass=file

audit(1138664845.191:124): avc:  denied  { getattr } for  pid=2740 comm="hald"
name="/" dev=hda3 ino=2 scontext=system_u:system_r:hald_t:s0
tcontext=system_u:object_r:default_t:s0 tclass=dir

audit(1138664932.572:135): avc:  denied  { execmod } for  pid=3545
comm="thunderbird-bin" name="libtraybiff.so" dev=hda3 ino=2813106
scontext=user_u:system_r:unconfined_t:s0 tcontext=user_u:object_r:default_t:s0
tclass=file
^ This i think is a thunderbird extension I installed.

Comment 1 Daniel Walsh 2006-01-31 15:02:09 UTC
This machine is badly mislabled.

touch /.autorelabel
reboot


Comment 2 Orion Poplawski 2006-01-31 17:10:53 UTC
Still lots of messages:

audit(1138726197.540:76): avc:  denied  { search } for  pid=1423
comm="pam_console_app" name="var" dev=hda8 ino=1269217
scontext=system_u:system_r:pam_console_t:s0-s0:c0.c255
tcontext=system_u:object_r:file_t:s0 tclass=dir
audit(1138726231.026:78): avc:  denied  { getattr } for  pid=1541
comm="setfiles" name="rhgb-console" dev=ramfs ino=4174
scontext=system_u:system_r:setfiles_t:s0 tcontext=system_u:object_r:ramfs_t:s0
tclass=fifo_file
audit(1138726231.026:79): avc:  denied  { getattr } for  pid=1541
comm="setfiles" name="xorg.log" dev=ramfs ino=4137
scontext=system_u:system_r:setfiles_t:s0 tcontext=system_u:object_r:ramfs_t:s0
tclass=file
audit(1138726231.026:80): avc:  denied  { getattr } for  pid=1541
comm="setfiles" name="rhgb-socket" dev=ramfs ino=4113
scontext=system_u:system_r:setfiles_t:s0 tcontext=system_u:object_r:ramfs_t:s0
tclass=sock_file
audit(1138726767.635:81): avc:  denied  { read write } for  pid=1614 comm="sadc"
name="0" dev=devpts ino=2 scontext=system_u:system_r:sysstat_t:s0
tcontext=system_u:object_r:devpts_t:s0 tclass=chr_file
audit(1138726767.887:82): avc:  denied  { getattr } for  pid=1624
comm="readahead" name="0" dev=devpts ino=2
scontext=system_u:system_r:readahead_t:s0 tcontext=system_u:object_r:devpts_t:s0
tclass=chr_file
audit(1138726767.891:83): avc:  denied  { dac_override } for  pid=1624
comm="readahead" capability=1 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:system_r:readahead_t:s0 tclass=capability
audit(1138726768.319:84): avc:  denied  { read } for  pid=1624 comm="readahead"
name="display" dev=ramfs ino=4111 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:object_r:ramfs_t:s0 tclass=file
audit(1138726768.319:85): avc:  denied  { read } for  pid=1624 comm="readahead"
name="rhgb-console" dev=ramfs ino=4174 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:object_r:ramfs_t:s0 tclass=fifo_file
audit(1138726778.624:88): avc:  denied  { dac_override } for  pid=1624
comm="readahead" capability=1 scontext=system_u:system_r:readahead_t:s0
tcontext=system_u:system_r:readahead_t:s0 tclass=capability
audit(1138726779.164:89): avc:  denied  { read write } for  pid=2045
comm="hid2hci" name="001" dev=tmpfs ino=3818
scontext=system_u:system_r:bluetooth_t:s0 tcontext=system_u:object_r:device_t:s0
tclass=chr_file
audit(1138726779.164:90): avc:  denied  { ioctl } for  pid=2045 comm="hid2hci"
name="001" dev=tmpfs ino=3818 scontext=system_u:system_r:bluetooth_t:s0
tcontext=system_u:object_r:device_t:s0 tclass=chr_file
audit(1138726781.340:91): avc:  denied  { search } for  pid=2095
comm="dnsdomainname" name="run" dev=hda9 ino=65281
scontext=system_u:system_r:hostname_t:s0 tcontext=system_u:object_r:var_run_t:s0
tclass=dir
audit(1138726781.340:92): avc:  denied  { search } for  pid=2095
comm="dnsdomainname" name="nscd" dev=hda9 ino=65287
scontext=system_u:system_r:hostname_t:s0
tcontext=system_u:object_r:nscd_var_run_t:s0 tclass=dir
audit(1138726791.145:93): avc:  denied  { getattr } for  pid=2722
comm="readahead" name="0" dev=devpts ino=2
scontext=system_u:system_r:readahead_t:s0 tcontext=system_u:object_r:devpts_t:s0
tclass=chr_file
audit(1138726799.957:94): avc:  denied  { getattr } for  pid=2761 comm="hald"
name="/" dev=hda3 ino=2 scontext=system_u:system_r:hald_t:s0
tcontext=system_u:object_r:default_t:s0 tclass=dir
audit(1138726947.139:95): avc:  denied  { getattr } for  pid=2761 comm="hald"
name="/" dev=hda3 ino=2 scontext=system_u:system_r:hald_t:s0
tcontext=system_u:object_r:default_t:s0 tclass=dir
audit(1138727067.598:104): avc:  denied  { execmod } for  pid=3784
comm="firefox-bin" name="libflashplayer.so" dev=hda3 ino=2718299
scontext=user_u:system_r:unconfined_t:s0 tcontext=system_u:object_r:default_t:s0
tclass=file
audit(1138727100.988:105): avc:  denied  { getattr } for  pid=2761 comm="hald"
name="/" dev=hda3 ino=2 scontext=system_u:system_r:hald_t:s0
tcontext=system_u:object_r:default_t:s0 tclass=dir
audit(1138727107.417:106): avc:  denied  { read } for  pid=4265 comm="ifconfig"
name="[9004]" dev=pipefs ino=9004 scontext=user_u:system_r:ifconfig_t:s0
tcontext=system_u:system_r:crond_t:s0-s0:c0.c255 tclass=fifo_file
audit(1138727107.421:107): avc:  denied  { write } for  pid=4265 comm="ifconfig"
name="cf_cynosure_cora_nwra_com_2006-01-31--10-00-12" dev=hda9 ino=49053
scontext=user_u:system_r:ifconfig_t:s0 tcontext=user_u:object_r:var_t:s0 tclass=file
audit(1138727107.777:108): avc:  denied  { read } for  pid=4279 comm="ifconfig"
name="[9004]" dev=pipefs ino=9004 scontext=user_u:system_r:ifconfig_t:s0
tcontext=system_u:system_r:crond_t:s0-s0:c0.c255 tclass=fifo_file
audit(1138727108.665:109): avc:  denied  { write } for  pid=4292 comm="ntpdate"
name="cf_cynosure_cora_nwra_com_2006-01-31--10-00-12" dev=hda9 ino=49053
scontext=user_u:system_r:ntpd_t:s0 tcontext=user_u:object_r:var_t:s0 tclass=file
audit(1138727108.405:110): avc:  denied  { write } for  pid=4294 comm="ntpd"
name="[11792]" dev=pipefs ino=11792 scontext=user_u:system_r:ntpd_t:s0
tcontext=user_u:system_r:unconfined_t:s0 tclass=fifo_file


Comment 3 Daniel Walsh 2006-01-31 19:01:17 UTC
These look like bugs from before the relabel.  Clear the log files, reboot and
then see if you have AVC messages.  libflashplayer.so should be labeled
textrel_shlib_t.  What file system are you using?

Dan