Bug 467380

Summary: AVC's when using an iscsi disk (iscsid)
Product: [Fedora] Fedora Reporter: Hans de Goede <hdegoede>
Component: selinux-policy-targetedAssignee: Daniel Walsh <dwalsh>
Status: CLOSED RAWHIDE QA Contact: Ben Levenson <benl>
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: poelstra
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-10-27 14:04:05 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 438943    

Description Hans de Goede 2008-10-17 08:41:14 UTC
Description of problem:
When using an iscsi disk, and thus running iscsid the following avc's are repeatedly entered into dmesg / audit.log:

type=AVC msg=audit(1224228653.374:5): avc:  denied  { search } for  pid=1898 comm="iscsid" name="iscsi" dev=sdc1 ino=468030 scontext=system_u:system_r:iscsid_t:s0 tcontext=system_u:object_r:iscsi_lock_t:s0 tclass=dir
type=SYSCALL msg=audit(1224228653.374:5): arch=40000003 syscall=5 success=no exit=-13 a0=806c66b a1=42 a2=1b6 a3=bfe31390 items=0 ppid=1894 pid=1898 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iscsid" exe="/sbin/iscsid" subj=system_u:system_r:iscsid_t:s0 key=(null)


type=AVC msg=audit(1224229733.361:3010): avc:  denied  { sys_admin } for  pid=1550 comm="iscsid" capability=21 scontext=system_u:system_r:iscsid_t:s0 tcontext=system_u:system_r:iscsid_t:s0 tclass=capability

Comment 1 Daniel Walsh 2008-10-27 14:04:05 UTC
Fixed in selinux-policy-3.5.13-7.fc10