Bug 439021
Summary: | genhomedircon generates avc messages | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Jeff Moyer <jmoyer> |
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED WONTFIX | QA Contact: | |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | 5.1 | CC: | ikent |
Target Milestone: | rc | Keywords: | Reopened |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2008-03-29 11:39:07 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jeff Moyer
2008-03-26 15:53:06 UTC
THis is caused by you not setting the allow_ypbind boolean. setsebool -P allow_ypbind=1 Should fix. And service ypbind start/stop will set and unset that variable. As far as I know, I shouldn't have to set it manually. More specifically, I don't call genhomedircon, it seems to get called on my behalf when running something else (service ypbind start/stop maybe?). Dan, can you comment on this? The script in question only does a 'service ypbind start', no stop, no restart. It is also the first script in the test run to start ypbind. Correction, we run 'service ypbind stop' first, and at that time the service was not previously running. Yes the init script is setting the boolean but it is too late, and the AVC's actually are against the command that is setting the boolean. setsebool allow_ypbind 1 execs genhomedircon. So this is generating the AVC messages. It is better to just set the boolean permanently. |