Bug 531374
| Summary: | SELinux is preventing consoletype (consoletype_t) "read write" pppd_t. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Egor Kuropatkin <nkrntlnhtn> |
| Component: | ppp | Assignee: | Jiri Skala <jskala> |
| Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | medium | Docs Contact: | |
| Priority: | low | ||
| Version: | 12 | CC: | aglotov, chenhuan.gt, dwalsh, id.eagle.id, jskala, mgrepl, natobk18, tsukinokage |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | i386 | ||
| OS: | Linux | ||
| Whiteboard: | setroubleshoot_trace_hash:ed4f4a51157be798e801beef4e5fdec410bb6b8cfd473d88893ba3f5830a4f18 | ||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2009-12-03 06:58:25 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Egor Kuropatkin
2009-10-27 22:13:50 UTC
pppd is leaking the file descriptor to the packet_socket. It should close this using fcntl on exec. Egor, you can ignore this, as It should not effect your functionality. You can add a rule using audit2allow if you want the message to stop. # grep avc /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Hi, I can't reproduce AVC denial. I tried to make changes mentioned by Daniel. Could you test it if there is some progress? The scratch build is available in koji: http://koji.fedoraproject.org/koji/taskinfo?taskID=1796872 Thanks, regards Jiri This bug appears to have been reported against 'rawhide' during the Fedora 12 development cycle. Changing version to '12'. More information and reason for this action is here: http://fedoraproject.org/wiki/BugZappers/HouseKeeping *** Bug 538154 has been marked as a duplicate of this bug. *** *** Bug 524174 has been marked as a duplicate of this bug. *** I have other sealerts in audit.log, what's the commands only for consoletype? Not sure what you mean by the question. May I use grep avc /var/log/audit/audit.log | grep consoletype | audit2allow -M mypol instead of the first command? yes *** This bug has been marked as a duplicate of bug 541107 *** |