| Summary: | SELinux is preventing /usr/sbin/dnsmasq from read access on the file nm-dns-dnsmasq.conf. | ||||||
|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | simon | ||||
| Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> | ||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||
| Severity: | unspecified | Docs Contact: | |||||
| Priority: | unspecified | ||||||
| Version: | 15 | CC: | dominick.grift, dwalsh, jistone, mgrepl | ||||
| Target Milestone: | --- | ||||||
| Target Release: | --- | ||||||
| Hardware: | Unspecified | ||||||
| OS: | Unspecified | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2011-07-26 06:11:22 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Attachments: |
|
||||||
|
Description
simon
2011-05-28 22:07:59 UTC
This should be fixed here i believe: https://admin.fedoraproject.org/updates/selinux-policy-3.9.16-26.fc15 Yes, it should be fixed. I'm getting denied-getattr and denied-unlink on nm-dns-dnsmasq.conf using selinux-policy-3.9.16-34.fc15.noarch. Should this bug be reopened, or filed separately? I noticed in particular that when the file is first created it has context NetworkManager_var_run_t, but restorecon puts it back to var_run_t. I see no special rules for this file in semanage fcontext. What avc msgs are you getting? type=AVC msg=audit(1311446980.946:9756): avc: denied { getattr } for pid=984 comm="NetworkManager" path="/run/nm-dns-dnsmasq.conf" dev=tmpfs ino=215168 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:var_run_t:s0 tclass=file
type=AVC msg=audit(1311446980.946:9757): avc: denied { unlink } for pid=984 comm="NetworkManager" name="nm-dns-dnsmasq.conf" dev=tmpfs ino=215168 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:var_run_t:s0 tclass=file
I did a chcon back to NetworkManager_var_run_t, and since then it's been fine.
Any idea how it got labeled this? Were you running any tools at the command line to start the network? Hmm, I almost always use nm-applet to manage connections. However, recently I was tinkering with loading/unloading e1000e for some driver issues I was having, so maybe NM got confused somewhere in that. I didn't investigate the sealert for a while at first, because the network still seemed to be working, until I noticed that my local hosts weren't resolving anymore while I was on the VPN. But now dns-dnsmasq is working again, so I guess I'll just watch to see if it happens again... ok, could you open the bug if the problem occurs again. |