Bug 1224405 - AVCs starting hostapd
Summary: AVCs starting hostapd
Keywords:
Status: CLOSED EOL
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: 22
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-05-22 20:32 UTC by Tom Hughes
Modified: 2019-08-09 11:14 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2016-07-19 14:12:43 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
Log of AVCs (10.77 KB, text/plain)
2015-05-22 20:32 UTC, Tom Hughes
no flags Details

Description Tom Hughes 2015-05-22 20:32:26 UTC
Created attachment 1028930 [details]
Log of AVCs

Description of problem:

A number of AVCs are being reported for hostapd in F22 which prevent it starting. The log is attached.

Version-Release number of selected component (if applicable):

selinux-policy-targeted-3.13.1-126.fc22.noarch
hostapd-2.3-4.fc22.i686

Comment 1 Tom Hughes 2015-06-29 13:28:10 UTC
I have now found another AVC which was hiding behind a dontaudit rule:

time->Mon Jun 29 10:39:34 2015
type=PROCTITLE msg=audit(1435570774.085:16533): proctitle=2F7573722F7362696E2F686F7374617064002F6574632F686F73746170642F686F73746170642E636F6E66002D50002F72756E2F686F73746170642E706964002D42
type=SYSCALL msg=audit(1435570774.085:16533): arch=40000003 syscall=102 success=yes exit=36 a0=10 a1=bf93c910 a2=b777d000 a3=90517e8 items=0 ppid=1 pid=7241 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="hostapd" exe="/usr/sbin/hostapd" subj=system_u:system_r:hostapd_t:s0 key=(null)
type=AVC msg=audit(1435570774.085:16533): avc:  denied  { search } for  pid=7241 comm="hostapd" name="phy7" dev="debugfs" ino=5626659 scontext=system_u:system_r:hostapd_t:s0 tcontext=system_u:object_r:debugfs_t:s0 tclass=dir permissive=1

This one is particularly nasty because, due to a kernel bug, once triggered there is an invalid pointer in the kernel which may later be dereferenced causing an oops.

Comment 2 Fedora End Of Life 2016-07-19 14:12:43 UTC
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.


Note You need to log in before you can comment on or make changes to this bug.