Bug 861980

Summary: selinux, afs, and readahead
Product: Red Hat Enterprise Linux 6 Reporter: jcpunk
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED ERRATA QA Contact: Milos Malik <mmalik>
Severity: low Docs Contact:
Priority: unspecified    
Version: 6.3CC: csieh, dwalsh, mmalik
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-02-21 08:31:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description jcpunk 2012-10-01 13:51:07 UTC
Description of problem:
The following audit message is sometimes generated on my system.

avc:  denied  { search } for  pid=381 comm="readahead-colle" name="openafs" dev=proc ino=4026532214 scontext=system_u:system_r:readahead_t:s0 tcontext=system_u:object_r:proc_afs_t:s0 tclass=dir

I'm not 100% sure that readahead should be assisting with these reads.

Version-Release number of selected component (if applicable): selinux-policy-targeted-3.7.19-155.el6_3.4.noarch.rpm


How reproducible: 50%


Steps to Reproduce:
1. load afs
2. browse around a bit
3. set a home dir to afs space
4. reboot
5. login as user from #3
6. check audit log for errors
  
Actual results:
errors in audit log

Expected results:
no audit log errors

Additional info:
The selinux package provides a number of policy componants for afs.
policy/modules/services/afs.if
policy/modules/services/afs.te
policy/modules/kernel/kernel.te
policy/modules/kernel/kernel.if
policy/modules/kernel/filesystem.te
man/man8/afs_selinux.8

Comment 2 Daniel Walsh 2012-10-08 20:31:43 UTC
I don't see any problem with allowing readahead to list all of proc.

Just added fix for RHEL7/F18

Comment 7 errata-xmlrpc 2013-02-21 08:31:01 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-0314.html