Bug 1158835 - selinux warning on logrotate on F21
Summary: selinux warning on logrotate on F21
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 21
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-10-30 10:41 UTC by Nikos Mavrogiannopoulos
Modified: 2015-01-02 22:15 UTC (History)
6 users (show)

Fixed In Version: selinux-policy-3.13.1-99.fc21
Clone Of:
Environment:
Last Closed: 2014-12-03 17:15:20 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
The details output (5.61 KB, text/plain)
2014-10-30 10:41 UTC, Nikos Mavrogiannopoulos
no flags Details

Description Nikos Mavrogiannopoulos 2014-10-30 10:41:58 UTC
Created attachment 952055 [details]
The details output

After installing F21 I got the following popup:
SELinux has detected a problem.

The source process: /usr/sbin/logrotate
Attempted this access: create
On this file: logrotate.status.tmp

That is a system deamon which I didn't install separately and shouldn't have generated any warning.

Comment 1 Lukas Vrabec 2014-10-30 11:45:51 UTC
Thank you Nikos, 
We know about this issue.

Comment 2 Lukas Vrabec 2014-10-30 12:42:45 UTC
commit 0ed7da1ba2b92e9f7065329fe2f1972fe9805bef
Author: Lukas Vrabec <lvrabec>
Date:   Thu Oct 30 12:52:07 2014 +0100

    Label also logrotate.status.tmp as logrotate_var_lib_t. BZ(1158835

https://github.com/selinux-policy/selinux-policy/commit/19d2ea0080e1481371c6e4d265fbeacad09074a2

Comment 3 Fedora Update System 2014-11-21 12:24:01 UTC
selinux-policy-3.13.1-99.fc21 has been submitted as an update for Fedora 21.
https://admin.fedoraproject.org/updates/selinux-policy-3.13.1-99.fc21

Comment 4 Fedora Update System 2014-12-03 17:15:20 UTC
selinux-policy-3.13.1-99.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 5 Alexandru C 2015-01-02 12:42:51 UTC
this keeps popping up everyday "SELinux is preventing logrotate from read access on the directory /var/cache/dnf."
Is it ok to allow logrotate read access ?

Comment 6 Daniel Walsh 2015-01-02 22:15:52 UTC
Yes, we are working on another bugzilla to get the log file moved out of /var/cache/dnf into a more appropriate directory under /var/log


Note You need to log in before you can comment on or make changes to this bug.