Bug 559355

Summary: allow dhcpc_t net_conf_t relabelfrom for dhclient
Product: Red Hat Enterprise Linux 5 Reporter: Joey Boggs <jboggs>
Component: selinux-policy-targetedAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED ERRATA QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: medium Docs Contact:
Priority: low    
Version: 5.5CC: dwalsh, mmalik, vbian
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2010-03-30 07:51:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 557667    
Attachments:
Description Flags
Miroslav add this patch from Rawhide to allow dhcpc_t to relabelto/from net_conf_t none

Description Joey Boggs 2010-01-27 20:48:07 UTC
Description of problem:
When restarting network services the following errors are in dmesg

Version-Release number of selected component (if applicable):
selinux-policy-targeted-2.4.6-270.el5

How reproducible:
- service network restart

  
Actual results:

type=1400 audit(1264442977.738:6): avc:  denied  { relabelfrom } for  pid=5752
comm="cp" name="ntp.conf.predhclient" dev=tmpfs ino=18379
scontext=system_u:system_r:dhcpc_t:s0 tcontext=system_u:object_r:net_conf_t:s0
tclass=file


Expected results:
No error messages

Comment 1 Daniel Walsh 2010-01-27 20:49:46 UTC
Created attachment 387176 [details]
Miroslav add this patch from Rawhide to allow dhcpc_t to relabelto/from net_conf_t

Comment 3 Miroslav Grepl 2010-01-28 16:13:49 UTC
Fixed in selinux-policy-2.4.6-271.el5

Comment 5 Joey Boggs 2010-01-29 16:17:04 UTC
updated policy works for me

Comment 6 Joey Boggs 2010-01-29 16:22:21 UTC
*** Bug 557667 has been marked as a duplicate of this bug. ***

Comment 9 errata-xmlrpc 2010-03-30 07:51:02 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHBA-2010-0182.html