Bug 506057

Summary: iscsid generates lots of AVC messages
Product: Red Hat Enterprise Linux 5 Reporter: michal novacek <mnovacek>
Component: selinux-policyAssignee: Daniel Walsh <dwalsh>
Status: CLOSED ERRATA QA Contact: BaseOS QE <qe-baseos-auto>
Severity: medium Docs Contact:
Priority: low    
Version: 5.3CC: mmalik
Target Milestone: rc   
Target Release: ---   
Hardware: ia64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-09-02 08:00:48 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Part of the audit.log
none
This is avc messages log from the failed test in rhts. none

Description michal novacek 2009-06-15 12:38:58 UTC
Created attachment 347928 [details]
Part of the audit.log

Description of problem:

I encountered this problem when testing new release of iscsid. There is a bunch of AVC messages generated when I do simple login/logout to scsi target


Version-Release number of selected component (if applicable): iscsi-initiator-6.2.0.871-0.5.el5

How reproducible: always

Steps to Reproduce:
1. install iscsi-initiator-6.2.0.871-0.5.el5 from brew
2. use iscsiadm to log to torget
  
Actual results:
Bunch of AVC denial messages generated

Expected results:
No AVC messages generated.

Additional info:

Comment 1 Daniel Walsh 2009-06-15 19:25:15 UTC
You attached the /var/log/messages not /var/log/audit/audit.log

Are you testing with the latest selinux-policy-targeted?

Comment 2 michal novacek 2009-06-16 08:23:36 UTC
Created attachment 348057 [details]
This is avc messages log from the failed test in rhts.

Comment 3 michal novacek 2009-06-16 08:29:15 UTC
(In reply to comment #1)
> Are you testing with the latest selinux-policy-targeted?  

I'm using non-updated fresh install of rhel5-server-u3 on rhts which comes with selinux-policy-targeted-2.4.6-203.el5.

Comment 4 Daniel Walsh 2009-06-16 13:48:54 UTC
Ok this looks like this is still present in the 5.4 policy



Fixed in selinux-policy-2.4.6-247

Comment 5 michal novacek 2009-06-17 16:24:28 UTC
Thanks. Is it available as rpm somewhere?

Comment 11 errata-xmlrpc 2009-09-02 08:00:48 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2009-1242.html