Bug 460098

Summary: SELinux AVCs when updating from RHEL-5.2-Z repo
Product: Red Hat Enterprise Linux 5 Reporter: Jan Hutař <jhutar>
Component: yumAssignee: James Antill <james.antill>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: 5.4CC: dwalsh, jburke
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-01-20 16:44:18 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
Attachments:
Description Flags
SELinux AVCs when updating from RHEL-5.2-Z repo (e.g. "SELinux is preventing tzdata-update (tzdata_t) "write" to /var/lib/yum/transaction-done.2008-08-06.17:36.41 (var_lib_t).") none

Description Jan Hutař 2008-08-26 02:56:49 EDT
Created attachment 314965 [details]
SELinux AVCs when updating from RHEL-5.2-Z repo (e.g. "SELinux is preventing tzdata-update (tzdata_t) "write" to /var/lib/yum/transaction-done.2008-08-06.17:36.41 (var_lib_t).")

Description of problem:
Some time ago when updating RHEL-5.2 from RHEL-5.2-Z repo, jburke got following SELinux AVCs.

Z stream repo was http://porkchop.redhat.com/rel-eng/repos/RHEL-5.2-Z/i386/ and then just `yum upgrade`.


Version-Release number of selected component (if applicable):
selinux-policy-2.4.6-137.1.el5_2


How reproducible:
happened once while upgrading


Steps to Reproduce:
1. enable repo http://porkchop.redhat.com/rel-eng/repos/RHEL-5.2-Z/i386/
2. update RHEL-5.2 system from it


Actual results:
AVCs - see attachments


Expected results:
no AVCs


Additional info:
I'm not sure if this is a yum or SELinux problem, so please could you (jantill and dwalsh) comment?
Comment 1 Daniel Walsh 2008-08-26 09:20:56 EDT
Looks like a leaked file descriptor problem in yum/rpm

I don't think tzdata knows anything about 
/var/lib/yum/transaction-done.2008-08-06.17:36.41 (var_lib_t).")
Comment 2 James Antill 2008-08-26 10:10:08 EDT
 Yeh, thanks for finding that, this patch should fix it:

http://fedorapeople.org/~james/yum/patches/yum-close-on-exec-transaction-done.patch

...it's not made it into upstream 3.2.19 (releasing atm.) so it'll be a back port of the first 3.2.20 commit for us (also means Fedora won't be getting it for a month or two).
 I don't see any reason to not put it in the 5.3 rebase though, so I've added my flags.
Comment 4 Fedora Update System 2008-08-27 14:02:16 EDT
yum-3.2.19-1.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/yum-3.2.19-1.fc8
Comment 5 Fedora Update System 2008-08-27 14:03:42 EDT
yum-3.2.19-1.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/yum-3.2.19-1.fc9
Comment 7 Fedora Update System 2008-09-10 02:58:46 EDT
yum-3.2.19-3.fc8 has been pushed to the Fedora 8 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 8 Fedora Update System 2008-09-10 02:59:12 EDT
yum-3.2.19-3.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 10 Fedora Update System 2008-12-01 10:38:21 EST
yum-3.2.20-4.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/yum-3.2.20-4.fc9
Comment 11 Fedora Update System 2008-12-02 20:26:11 EST
yum-3.2.20-4.fc9 has been pushed to the Fedora 9 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing-newkey update yum'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-10658
Comment 13 Fedora Update System 2008-12-08 12:08:13 EST
yum-3.2.20-5.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/yum-3.2.20-5.fc9
Comment 14 Fedora Update System 2008-12-09 06:37:54 EST
yum-3.2.20-5.fc9 has been pushed to the Fedora 9 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing-newkey update yum'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-11056
Comment 17 Fedora Update System 2008-12-17 19:31:43 EST
yum-3.2.20-5.fc9 has been pushed to the Fedora 9 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 18 errata-xmlrpc 2009-01-20 16:44:18 EST
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2009-0176.html