Bug 219983

Summary: hald denials
Product: [Fedora] Fedora Reporter: Dave Jones <davej>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED RAWHIDE QA Contact: Ben Levenson <benl>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: dwalsh, pfrields
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-12-18 17:18:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dave Jones 2006-12-18 02:35:08 UTC
during boot, when hal starts up I see these logged to the screen.


Dec 17 20:26:57 silver kernel: audit(1166408816.981:4): avc:  denied  { search }
for  pid=1941 comm="hald" name="irq" dev=proc ino=-268435212 scontext=system
_u:system_r:hald_t:s0 tcontext=system_u:object_r:sysctl_irq_t:s0 tclass=dir
Dec 17 20:26:57 silver kernel: audit(1166408817.017:5): avc:  denied  { search }
for  pid=1941 comm="hald" name="irq" dev=proc ino=-268435212 scontext=system
_u:system_r:hald_t:s0 tcontext=system_u:object_r:sysctl_irq_t:s0 tclass=dir
Dec 17 20:26:57 silver kernel: audit(1166408817.049:6): avc:  denied  { search }
for  pid=1941 comm="hald" name="irq" dev=proc ino=-268435212 scontext=system
_u:system_r:hald_t:s0 tcontext=system_u:object_r:sysctl_irq_t:s0 tclass=dir
Dec 17 20:26:57 silver kernel: audit(1166408817.089:7): avc:  denied  { search }
for  pid=1941 comm="hald" name="irq" dev=proc ino=-268435212 scontext=system
_u:system_r:hald_t:s0 tcontext=system_u:object_r:sysctl_irq_t:s0 tclass=dir
Dec 17 20:26:57 silver kernel: audit(1166408817.129:8): avc:  denied  { search }
for  pid=1941 comm="hald" name="irq" dev=proc ino=-268435212 scontext=system
_u:system_r:hald_t:s0 tcontext=system_u:object_r:sysctl_irq_t:s0 tclass=dir
Dec 17 20:26:57 silver kernel: audit(1166408817.613:9): avc:  denied  { read
write } for  pid=1947 comm="hal-storage-cle" name=".hal-mtab-lock" dev=dm-0 ino=
4554755 scontext=system_u:system_r:hald_t:s0
tcontext=system_u:object_r:default_t:s0 tclass=file

Comment 1 Daniel Walsh 2006-12-18 17:18:40 UTC
This looks like an out of date policy.

.htl-mtab-lock has the wrong label and hal can read sysctl_irq_t on my machine now.

selinux-policy-2.4.6-11.el5