Bug 224441
Summary: | AVC while updating machine | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Steve Grubb <sgrubb> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 5.0 | CC: | benl, dwalsh, jlaska |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | RHBA-2007-0544 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-11-07 16:38:09 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Steve Grubb
2007-01-25 18:45:51 UTC
Fixed in selinux-policy-2.4.6-31.el5 This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux major release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Major release. This request is not yet committed for inclusion. I have been asked to hold off til after release. So pushing it back so we can build it for Day 0 Release. I'm trying to inspect the fix for this issue, as well as get a sense for what selinux prevented in this case. Any thoughts? One of the libraries used in semodule requested CAP_SYS_RESOURCE capability. Probably to override a resource limit. The kernel denied it, and the app seemed to continue running fine. The following defines what CAP_SYS_RESOURCE is: CAP_SYS_RESOURCE: · Override resource limits. Set resource limits; · Override quota limits; · Override reserved space on ext2 filesystem; · Modify data journaling mode on ext3 filesystem (uses journaling resources); NOTE: ext2 honors fsuid when checking for resource overrides, so you can override using fsuid too; · Override size restrictions on IPC message queues; · Allow more than 64hz interrupts from the real?time clock; · Override max number of consoles on console allocation; · Override max number of keymaps. Sounds like the app was able to successfully recover ... thank you for that analysis. QA_ACK for 5.1 An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2007-0544.html |