Hide Forgot
Description of problem: * ipmiseld uses too powerful SELinux domain Version-Release number of selected component (if applicable): freeipmi-ipmiseld-1.2.9-2.el7.x86_64 selinux-policy-3.12.1-105.el7.noarch selinux-policy-devel-3.12.1-105.el7.noarch selinux-policy-doc-3.12.1-105.el7.noarch selinux-policy-minimum-3.12.1-105.el7.noarch selinux-policy-mls-3.12.1-105.el7.noarch selinux-policy-targeted-3.12.1-105.el7.noarch How reproducible: always Steps to Reproduce: # service ipmiseld status Redirecting to /bin/systemctl status ipmiseld.service ipmiseld.service - IPMI SEL syslog logging daemon Loaded: loaded (/usr/lib/systemd/system/ipmiseld.service; disabled) Active: inactive (dead) # service ipmiseld start Redirecting to /bin/systemctl start ipmiseld.service # service ipmiseld status Redirecting to /bin/systemctl status ipmiseld.service ipmiseld.service - IPMI SEL syslog logging daemon Loaded: loaded (/usr/lib/systemd/system/ipmiseld.service; disabled) Active: active (running) since Tue 2013-12-03 09:44:10 CET; 1s ago Process: 4987 ExecStart=/usr/sbin/ipmiseld (code=exited, status=0/SUCCESS) Main PID: 4989 (ipmiseld) CGroup: /system.slice/ipmiseld.service └─4989 /usr/sbin/ipmiseld Dec 03 09:44:10 rhel70.localdomain systemd[1]: Started IPMI SEL syslog loggi.... Hint: Some lines were ellipsized, use -l to show in full. # ps -efZ | grep ipmiseld system_u:system_r:init_t:s0 root 4989 1 38 09:44 ? 00:00:03 /usr/sbin/ipmiseld unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 root 5003 2416 0 09:44 pts/0 00:00:00 grep --color=auto ipmiseld # Actual results: * ipmiseld runs as init_t Expected results: * ipmiseld runs in its own SELinux domain
commit dee0ab128c1730828e041645811da995a2929f0b Author: Miroslav Grepl <mgrepl> Date: Thu Dec 5 17:11:53 2013 +0100 Add policy for freeipmi services
commit 635d073c3124218716c94266a511366d3cb69de6 Author: Miroslav Grepl <mgrepl> Date: Thu Dec 12 15:00:06 2013 +0100 Update freeipmi policy
This request was resolved in Red Hat Enterprise Linux 7.0. Contact your manager or support representative in case you have further questions about the request.