Bug 395971

Summary: SELinux is preventing /usr/sbin/groupadd (groupadd_t) "write" to /dev/null (var_lib_t). durring mock build
Product: [Fedora] Fedora Reporter: Russell Harrison <fedora>
Component: selinux-policyAssignee: David Cantrell <dcantrell>
Status: CLOSED NEXTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: low    
Version: 7CC: mebrown
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-11-26 20:20:57 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
setroubleshoot alert groupadd output none

Description Russell Harrison 2007-11-22 17:56:05 UTC
I see several selinux alert messages during a mock build.

I'm attaching the alert file from setroubleshoot

Comment 1 Russell Harrison 2007-11-22 17:56:05 UTC
Created attachment 267161 [details]
setroubleshoot alert groupadd output

Comment 2 Michael E Brown 2007-11-22 18:34:13 UTC
This should be against selinux-policy, not mock.


Comment 3 Michael E Brown 2007-11-22 18:35:46 UTC
As an aside, this doesnt prevent mock from functioning, it simply produces log
messages.

Comment 4 Michael E Brown 2007-11-26 20:20:57 UTC
I have fixed this in mock by doing a "chcon
--reference=/dev/FILE  /mock/build/root/dev/FILE". 

This specific bug I am going to mark as FIXED - NEXTRELEASE. I dont intend to
make another release for a few weeks, at least. If you would like to check out
the fixed version, please look in the git repository for mock.