Description of problem: New avc for mythtv Version-Release number of selected component (if applicable): selinux-policy-3.12.1-106.fc20.noarch mythtv-common-0.27-3.fc20.x86_64 How reproducible: Steps to Reproduce: 1. 2. 3. Actual results: Expected results: Additional info: ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.120:11058): arch=c000003e syscall=257 success=no exit=-13 a0=ffffffffffffff9c a1=3354d7a67c a2=90800 a3=0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.120:11058): avc: denied { read } for pid=2477 comm="mythweb.pl" name="cpu" dev="sysfs" ino=37 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=dir ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.200:11059): arch=c000003e syscall=2 success=no exit=-13 a0=7f011aaff4f2 a1=80000 a2=1b6 a3=7fff8b638db0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.200:11059): avc: denied { read } for pid=2477 comm="mythweb.pl" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.203:11060): arch=c000003e syscall=109 success=no exit=-13 a0=0 a1=0 a2=100 a3=0 items=0 ppid=14620 pid=2477 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="mythweb.pl" exe="/usr/bin/perl" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.203:11060): avc: denied { setpgid } for pid=2477 comm="mythweb.pl" scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:system_r:httpd_mythtv_script_t:s0 tclass=process ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.210:11061): arch=c000003e syscall=2 success=no exit=-13 a0=7f90e12fb4f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2477 pid=2482 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="sh" exe="/usr/bin/bash" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.210:11061): avc: denied { read } for pid=2482 comm="sh" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.211:11062): arch=c000003e syscall=2 success=no exit=-13 a0=7f78a3c894f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2477 pid=2483 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="sh" exe="/usr/bin/bash" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.211:11062): avc: denied { read } for pid=2483 comm="sh" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file ---- time->Thu Jan 2 07:11:16 2014 type=SYSCALL msg=audit(1388675476.941:11063): arch=c000003e syscall=2 success=no exit=-13 a0=7f9623e9a4f2 a1=80000 a2=1b6 a3=0 items=0 ppid=2483 pid=2485 auid=4294967295 uid=48 gid=48 euid=48 suid=48 fsuid=48 egid=48 sgid=48 fsgid=48 ses=4294967295 tty=(none) comm="ffmpeg" exe="/usr/bin/ffmpeg" subj=system_u:system_r:httpd_mythtv_script_t:s0 key=(null) type=AVC msg=audit(1388675476.941:11063): avc: denied { read } for pid=2485 comm="ffmpeg" name="passwd" dev="dm-1" ino=689673 scontext=system_u:system_r:httpd_mythtv_script_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
0bedea3ea57dbc1c03b85dacbae12256ffb1954e fixes this in git.
back ported to F20 and F19.
selinux-policy-3.12.1-116.fc20 has been submitted as an update for Fedora 20. https://admin.fedoraproject.org/updates/selinux-policy-3.12.1-116.fc20
Package selinux-policy-3.12.1-116.fc20: * should fix your issue, * was pushed to the Fedora 20 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing selinux-policy-3.12.1-116.fc20' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2014-0806/selinux-policy-3.12.1-116.fc20 then log in and leave karma (feedback).
selinux-policy-3.12.1-116.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please make note of it in this bug report.