Bug 732727

Summary: avc init_t insmod_t
Product: [Fedora] Fedora Reporter: Mads Kiilerich <mads>
Component: selinux-policy-targetedAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED ERRATA QA Contact: Ben Levenson <benl>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 16CC: dwalsh
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: selinux-policy-3.10.0-21.fc16 Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-07 03:20:02 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Attachments:
Description Flags
dmesg none

Description Mads Kiilerich 2011-08-23 11:51:40 UTC
Created attachment 519444 [details]
dmesg

With the latest f16 -testing I get an avc:

[   25.754412] avahi-daemon[978]: Found user 'avahi' (UID 70) and group 'avahi' (GID 70).
[   25.758773] avahi-daemon[978]: Successfully dropped root privileges.
[   25.760300] avahi-daemon[978]: avahi-daemon 0.6.30 starting up.
[   25.849039] type=1400 audit(1314094042.257:3): avc:  denied  { getattr } for  pid=999 comm="modprobe" path="socket:[14702]" dev=sockfs ino=14702 scontext=system_u:system_r:insmod_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket
[   25.852736] multipathd (998): /proc/998/oom_adj is deprecated, please use /proc/998/oom_score_adj instead.
[   25.860568] multipathd[998]: /etc/multipath.conf does not exist, blacklisting all devices.
[   25.863630] multipathd[998]: A sample multipath.conf file is located at
[   25.869433] multipathd[998]: /usr/share/doc/device-mapper-multipath-0.4.9/multipath.conf
[   25.872582] multipathd[998]: You can run /sbin/mpathconf to create or modify /etc/multipath.conf
[   25.874940] multipathd[998]: path checkers start up

It was for some reason not detected automatically.

selinux-policy-targeted-3.10.0-18.fc16.noarch
systemd-33-2.fc16.x86_64
kernel-3.1.0-0.rc3.git0.0.fc16.x86_64
avahi-0.6.30-3.fc16.x86_64
device-mapper-multipath-0.4.9-18.fc16.x86_64

Comment 1 Daniel Walsh 2011-08-24 03:09:43 UTC
Added dontaudit in selinux-policy-3.10.0-20.fc16

Comment 2 Fedora Update System 2011-08-24 11:39:18 UTC
selinux-policy-3.10.0-21.fc16 has been submitted as an update for Fedora 16.
https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-21.fc16

Comment 3 Fedora Update System 2011-08-24 22:46:15 UTC
Package selinux-policy-3.10.0-21.fc16:
* should fix your issue,
* was pushed to the Fedora 16 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.10.0-21.fc16'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-21.fc16
then log in and leave karma (feedback).

Comment 4 Fedora Update System 2011-09-07 03:19:27 UTC
selinux-policy-3.10.0-21.fc16 has been pushed to the Fedora 16 stable repository.  If problems still persist, please make note of it in this bug report.