Bug 485631
| Summary: | SELinux is preventing ntpd (ntpd_t) "read write" unconfined_t. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | D Levin <dashlevin> |
| Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | low | ||
| Version: | 10 | CC: | dashlevin, dwalsh, mgrepl |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | i386 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2009-05-01 17:50:45 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
D Levin
2009-02-15 16:20:38 UTC
This can be safely ignored, Are you using konsole for your terminal? Or were you using a graphical tool when this happened? It is most likely a leaked file descriptor, and SELinux is just complaining about it. It will be closed and ntpd was allowed to run normally. I was using gnome-terminal within the gnome desktop. When I double-clicked the date-time on the panel I got this failure. When I ran System -> Administration -> Date/Time no errors, but my time zone change did not take. Worked the second time. All is now OK. Let me restate. I now see that NTP consistently fails on boot (fails to sync before loading service). Checking event log shows the same error. Attempting to reconfigure NTP to prevent sync on boot also triggers same error. Since config does not change, I would say it's not not safe to ignore. If this is failing on boot you must be getting different avcs then the ones you attached above, since there would be no unconfined_t processes running on the machine at boot. unconfined_t is a user label. Please attach the /var/log/audit/audit.log after a boot. Is it still happening with current selinux-policy ? In this case please attach the /var/log/audit/audit.log after a boot. I am closing in current release on this one. Reopen if you have a reproducer I turned off enforcing when I encountered this (and other errors). I've been meaning to re-enable and answer your question, but have been busy. This resolution is fine. If it recurs, I will reopen. Thanks |