Bug 233220
Summary: | LSPP: readlink readlinkat missing obj context | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Debora Velarde <dvelarde> |
Component: | kernel | Assignee: | Eric Paris <eparis> |
Status: | CLOSED NOTABUG | QA Contact: | Martin Jenner <mjenner> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 5.0 | CC: | amy.griffis, iboverma, linda.knippers, sgrubb |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-03-22 16:25:56 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 224041 |
Description
Debora Velarde
2007-03-21 00:41:11 UTC
Adding amy to see if she has input. Looks like audit_inode inside fs/namei.c:do_path_lookup is conditionalized on retval = 0; I'm assuming link_path_walk is giving us a permission error. The 'old' obj that was logged was just leftover crap fixed in 223918 If we never actually drill down and find the inode we don't know what the obj is to be able to log it. Remember the failure is not always that we can't read the actual file /root/tmp/test_file_symlink but in this case we can't even get into /root and so we don't know the label on the actual symlink. I'm thinking NOTABUG.... That's right, if you couldn't traverse the directory tree to the object, audit doesn't have to log the object info. Other than that, I don't see a problem. For success I get: type=PATH msg=audit(1174578545.504:660): item=0 name="sym-low" inode=721268 dev=ee:00 mode=0120777 ouid=0 ogid=0 rdev=00:00 obj=staff_u:object_r:lspp_test_dir_t:s0 and failure: type=PATH msg=audit(1174578562.583:662): item=0 name="sym-high" inode=721267 dev=ee:00 mode=0120777 ouid=0 ogid=0 rdev=00:00 obj=staff_u:object_r:lspp_test_dir_t:s15:c0.c1023 This is the info for the symlinks themselves, not the object they point to. OK, if we change the file from /root to a different directory things work as expected. OK to close. |