Bug 472903
Summary: | [RHEL5.3] SELinux AVC Denied: Not allowing install of xen guest | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 5 | Reporter: | Jeff Burke <jburke> |
Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
Status: | CLOSED ERRATA | QA Contact: | Martin Jenner <mjenner> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 5.3 | CC: | dzickus, gozen, lwang, mgahagan, pbunyan, syeghiay, xen-maint |
Target Milestone: | rc | Keywords: | Regression, TestBlocker |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://rhts.redhat.com/cgi-bin/rhts/test_log.cgi?id=5303977 | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2009-01-20 21:30:06 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Jeff Burke
2008-11-25 15:32:54 UTC
Fixed in selinux-policy-2.4.6-194.el5 Unfortunately this issue still exists in RHEL5.3-Server-20081203.0 tree that has selinux-policy-2.4.6-197.el5 package: /sbin/ausearch -sv no -m AVC -m USER_AVC -m SELINUX_ERR -ts 12/4/2008 5:37:47 ---- time->Thu Dec 4 05:42:16 2008 type=SYSCALL msg=audit(1228387336.023:11): arch=c000003e syscall=42 success=no exit=-13 a0=b a1=7fffe82716c0 a2=6e a3=2b9fc40f8a30 items=0 ppid=4534 pid=5839 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=4294967295 comm="virsh" exe="/usr/bin/virsh" subj=system_u:system_r:xm_t:s0 key=(null) type=AVC msg=audit(1228387336.023:11): avc: denied { search } for pid=5839 comm="virsh" name="libvirt" dev=dm-0 ino=19333348 scontext=system_u:system_r:xm_t:s0 tcontext=system_u:object_r:virt_var_run_t:s0 tclass=dir Fixed in selinux-policy-2.4.6-198.el5 An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on therefore solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHBA-2009-0163.html |