Bug 236855
Summary: | LSPP: aide can't write its log file | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | George C. Wilson <ltcgcw> |
Component: | aide | Assignee: | Steve Conklin <sconklin> |
Status: | CLOSED ERRATA | QA Contact: | Tom Kincaid <tkincaid> |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 5.0 | CC: | dwalsh, iboverma, krisw, linda.knippers |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | RHSA-2007-0539 | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2007-09-04 14:03:02 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 224041 | ||
Attachments: |
Description
George C. Wilson
2007-04-18 00:47:24 UTC
Created attachment 152866 [details]
Adds /var/log/aide to spec file.
LSPP-specific aide configuration seems to be done outside the build tree. This
patch is directly against SPECS/aide.spec. Built but not tested.
Created attachment 152867 [details]
Sets aide log file path to /var/log/aide/aide.log
LSPP-specific aide configuration seems to be done outside the build tree. This
patch is directly against SOURCES/aide.conf. Built but not tested.
Created attachment 152868 [details]
Adds /var/log/aide and /var/log/aide/.* aide_t:SystemHigh fcontexts
Built but not tested.
Created attachment 152901 [details]
Adds /var/log/aide and /var/log/aide/.* aide_t:SystemHigh fcontexts
Tested previous patch and updated it. aide requires additional TE perms as
well. aide with the above 2 patches seems to work well with this patch.
aide-0.12-9 was built. I think we still need selinux-policy package built. Fixed in Selinus-policy- 2.4.6-60 Ok, looks like we are ready for re-test. Thanks. Thanks for making the changes. The aide package looks OK. The -60 policy adds the file contexts but not the additional TE perms in my 2nd attempt at the patch. So I still have to add a module with allow aide_t aide_log_t:dir { add_name write }; to permit aide to create its log file. I think we'll need that allow rule or an interface that provides the same permissions. This looks good with the 62 policy. An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2007-0539.html |