Bug 312771
Summary: | AVCs related to hibernating | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Matthew Saltzman <mjs> |
Component: | selinux-policy-targeted | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Ben Levenson <benl> |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | 8 | ||
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Current | Doc Type: | Bug Fix |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2008-01-30 19:06:31 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Matthew Saltzman
2007-09-29 22:47:38 UTC
These should be fixed in selinux-policy-3.0.8-16 Still an issue with selinux-policy-targeted-3.0.8-16.fc8. avc: denied { read } for comm=alsactl dev=dm-0 egid=0 euid=0 exe=/sbin/alsactl exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=asound.state pid=4386 scontext=system_u:system_r:alsa_t:s0 sgid=0 subj=system_u:system_r:alsa_t:s0 suid=0 tclass=file tcontext=system_u:object_r:etc_runtime_t:s0 tty=(none) uid=0 avc: denied { setsched } for comm=pm-hibernate egid=0 euid=0 exe=/bin/bash exit=4 fsgid=0 fsuid=0 gid=0 items=0 pid=4117 scontext=system_u:system_r:hald_t:s0 sgid=0 subj=system_u:system_r:hald_t:s0 suid=0 tclass=process tcontext=system_u:system_r:kernel_t:s0 tty=(none) uid=0 avc: denied { write } for comm=alsactl dev=dm-0 egid=0 euid=0 exe=/sbin/alsactl exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=asound.state pid=4208 scontext=system_u:system_r:alsa_t:s0 sgid=0 subj=system_u:system_r:alsa_t:s0 suid=0 tclass=file tcontext=system_u:object_r:etc_runtime_t:s0 tty=(none) uid=0 Ok Try selinux-policy-targeted-3.0.8-17.fc8 You will either need to remove /etc/asound.state or restorecon it . The AVCs in Comment #2 still appear. For the alsa ones, the behavior changed across the restorecon (see below). Also still seeing the pm-hibernate AVC. Before: avc: denied { read } for comm=alsactl dev=dm-0 egid=0 euid=0 exe=/sbin/alsactl exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=asound.state pid=3559 scontext=system_u:system_r:alsa_t:s0 sgid=0 subj=system_u:system_r:alsa_t:s0 suid=0 tclass=file tcontext=system_u:object_r:etc_runtime_t:s0 tty=(none) uid=0 avc: denied { write } for comm=alsactl dev=dm-0 egid=0 euid=0 exe=/sbin/alsactl exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=asound.state pid=3373 scontext=system_u:system_r:alsa_t:s0 sgid=0 subj=system_u:system_r:alsa_t:s0 suid=0 tclass=file tcontext=system_u:object_r:etc_runtime_t:s0 tty=(none) uid=0 Restorecon results: # /sbin/restorecon -v asound.state /sbin/restorecon reset asound.state context system_u:object_r:etc_runtime_t:s0->system_u:object_r:etc_t:s0 After: avc: denied { write } for comm=alsactl dev=dm-0 egid=0 euid=0 exe=/sbin/alsactl exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=asound.state pid=3947 scontext=system_u:system_r:alsa_t:s0 sgid=0 subj=system_u:system_r:alsa_t:s0 suid=0 tclass=file tcontext=system_u:object_r:etc_t:s0 tty=(none) uid=0 Argh this is using /etc/alsa/asound.state. Fixed in selinux-policy-targeted-3.0.8-18.fc8 You can test it by adding the file context path semanage fcontext -a -t alsa_etc_rw_t /etc/alsa/asound\.state After running the semanage command and restorecon for /etc/alsa/asound.state, the alsa AVCs are gone. The pm-hibernate one is still there, though. I think this alsa one is also a problem in selinux-policy-targeted-2.6.4-45.fc7. Are you saying you are still seeing the hal setsched on kernel issue in rawhide. F8T3, fully updated as of this morning. kernel-2.6.23-0.217.rc9.git1.fc8.x86_64 hal-0.5.10-0.git20070925.fc8 selinux-policy-targeted-3.0.8-17.fc8 avc: denied { setsched } for comm=pm-hibernate egid=0 euid=0 exe=/bin/bash exit=4 fsgid=0 fsuid=0 gid=0 items=0 pid=4042 scontext=system_u:system_r:hald_t:s0 sgid=0 subj=system_u:system_r:hald_t:s0 suid=0 tclass=process tcontext=system_u:system_r:kernel_t:s0 tty=(none) uid=0 Bulk closing a old selinux policy bugs that were in the modified state. If the bug is still not fixed. Please reopen. |