| Summary: | sh (dhcpc_t) is attempting to "execute" to ./iptables (iptables_exec_t) | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | Raymond Rugemalira <mambo-ruge> |
| Component: | selinux-policy | Assignee: | Miroslav Grepl <mgrepl> |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
| Severity: | urgent | Docs Contact: | |
| Priority: | urgent | ||
| Version: | 5.8 | CC: | dwalsh, jpopelka, ksrot, mmalik |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | selinux-policy-2.4.6-317.el5 | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-02-21 05:48:12 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Raymond Rugemalira
2011-09-27 14:42:40 UTC
I have run restorecon -v '/etc/init.d/iptable' '/sbin/iptables' to no avail. I do not want to switch selinux off I am addding
optional_policy(`
tunable_policy(`dhcpc_exec_iptables',`
iptables_domtrans(dhcpc_t)
')
')
which we have in RHEL6. Which will allow it using
dhcpc_exec_iptables boolean
Fixed in selinux-policy-2.4.6-317.el5 (In reply to comment #3) > Fixed in selinux-policy-2.4.6-317.el5 Below is what I get when I run yum update selinux-policy-2.4.6-317.el5 Kindly instruct what to do. # yum update selinux-policy-2.4.6-317.el5 Loaded plugins: product-id, rhnplugin, security, subscription-manager Updating Red Hat repositories. Skipping security plugin, no data Setting up Update Process No Match for argument: selinux-policy-2.4.6-317.el5 No package selinux-policy-2.4.6-317.el5 available. No Packages marked for Update Yes, because this is a pre-release which is not available on rhn. (In reply to comment #5) > Yes, because this is a pre-release which is not available on rhn. You are being pretty criptic with me. Could you clarify where to get the pre-release so I can rectify the error? Where is the pre-release package? This pre-release is now available from http://people.redhat.com/dwalsh/SELinux/RHEL5/noarch/ Hi Raymond, could you please confirm that the issue is fixed with selinux-policy-2.4.6-317.el5? Thank you in advance. I installed the pre-release version ofselinux-policy-2.4.6-317.el5 from http://people.redhat.com/dwalsh/SELinux/RHEL5/noarch/ to no avail.The problem was not solved. You need to turn on the dhcpc_exec_iptables boolean. setsebool -P dhcpc_exec_iptables 1 # setsebool -P dhcpc_exec_iptables 1 libsemanage.dbase_llist_set: record not found in the database libsemanage.dbase_llist_set: could not set record value Could not change boolean dhcpc_exec_iptables Could not change policy booleans rpm -q selinux-policy Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2012-0158.html |