Bug 681364

Summary: Summary SELinux is preventing innd (innd_t) "sendto" to /var/run/news/ctlinndAp3amm (unconfined_crond_t). Detailed Description SELinux denied access requested by innd. It is not expected that this access is required by innd and this acces
Product: [Fedora] Fedora Reporter: dhiraj <dhirajrode>
Component: innAssignee: Nikola Pajkovsky <npajkovs>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 8CC: dhoward, jochen, npajkovs, ovasik
Target Milestone: ---Keywords: SELinux
Target Release: ---   
Hardware: i686   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-03-02 06:31:09 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:

Description dhiraj 2011-03-01 22:48:38 UTC
Summary
    SELinux is preventing innd (innd_t) "sendto" to /var/run/news/ctlinndAp3amm
    (unconfined_crond_t).

Detailed Description
    SELinux denied access requested by innd. It is not expected that this access
    is required by innd and this access may signal an intrusion attempt. It is
    also possible that the specific version or configuration of the application
    is causing it to require additional access.

Allowing Access
    You can generate a local policy module to allow this access - see
    http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385 Or you can disable
    SELinux protection altogether. Disabling SELinux protection is not
    recommended. Please file a http://bugzilla.redhat.com/bugzilla/enter_bug.cgi
    against this package.

Additional Information        

Source Context                system_u:system_r:innd_t:s0
Target Context                unconfined_u:unconfined_r:unconfined_crond_t:s0
Target Objects                /var/run/news/ctlinndAp3amm [ unix_dgram_socket ]
Affected RPM Packages         
Policy RPM                    selinux-policy-3.0.8-44.fc8
Selinux Enabled               True
Policy Type                   targeted
MLS Enabled                   True
Enforcing Mode                Enforcing
Plugin Name                   plugins.catchall
Host Name                     localhost.localdomain
Platform                      Linux localhost.localdomain 2.6.23.1-42.fc8 #1 SMP
                              Tue Oct 30 13:55:12 EDT 2007 i686 i686
Alert Count                   1
First Seen                    Wed 02 Mar 2011 04:10:31 AM IST
Last Seen                     Wed 02 Mar 2011 04:10:31 AM IST
Local ID                      551bc3fa-22b4-49b9-9640-cb6aac014ce4
Line Numbers                  

Raw Audit Messages            

avc: denied { sendto } for comm=innd path=/var/run/news/ctlinndAp3amm pid=3662
scontext=system_u:system_r:innd_t:s0 tclass=unix_dgram_socket
tcontext=unconfined_u:unconfined_r:unconfined_crond_t:s0

Comment 1 Ondrej Vasik 2011-03-02 06:31:09 UTC
Fedora 8 is EOL for a long time, closing WONTFIX, please recheck with current supported Fedora and either report again or at least leave a comment here that the problem still exists.