Bug 989018

Summary: avc: denied { create } for pid=394 comm="systemd-tmpfile" name="loop-control"
Product: [Fedora] Fedora Reporter: Adam Williamson <awilliam>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: unspecified    
Version: rawhideCC: dominick.grift, dwalsh, mgrepl
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-07-29 10:30:57 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Adam Williamson 2013-07-26 23:03:18 UTC
This isn't showing up in the troubleshooter for some reason so filing it manually. I'm seeing this denial on boot when systemd tries to create /dev/loop-control , and I think that causes anything that tries to use a loop device later on to fail:

Jul 26 15:39:25 adam.localdomain systemd-tmpfiles[394]: Failed to create device node /dev/loop-control: Permission denied
Jul 26 15:39:25 adam.localdomain kernel: type=1400 audit(1374878365.880:8): avc:  denied  { create } for  pid=394 comm="systemd-tmpfile" name="loop-control" scontext=system_u:system_r:systemd_tmpfiles_t:s0 tcontext=system_u:object_r:loop_control_device_t:s0 tclass=chr_file
Jul 26 15:39:26 adam.localdomain systemd-tmpfiles[529]: Failed to create device node /dev/loop-control: Permission denied

Comment 1 Adam Williamson 2013-07-26 23:08:22 UTC
oh, sorry, forgot to mention, this is Rawhide:

selinux-policy-3.12.1-66.fc20.noarch
systemd-206-1.fc20.x86_64

Comment 2 Miroslav Grepl 2013-07-29 10:30:57 UTC
Should be fixed in the latest build.