Bug 132574 - mdadm and ntp policy problems
Summary: mdadm and ntp policy problems
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: rawhide
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: FC3Blocker
TreeView+ depends on / blocked
 
Reported: 2004-09-14 19:34 UTC by Daniel Reed
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2004-09-16 12:03:16 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Daniel Reed 2004-09-14 19:34:22 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.2)
Gecko/20040809 Epiphany/1.3.8

Description of problem:
Starting mdmonitor: audit(1095188105.721:0): avc:  denied  { read }
for  pid=2789 exe=/sbin/mdadm name=mdstat dev=proc ino=-268435080
scontext=user_u:system_r:unconfined_t
tcontext=system_u:object_r:proc_mdstat_t tclass=file


Starting ntpd:                                             [  OK  ]
audit(1095188122.323:0): avc:  denied  { name_bind } for  pid=3050
exe=/usr/sbin/ntpd src=682 scontext=user_u:system_r:ntpd_t
tcontext=system_u:object_r:reserved_port_t tclass=udp_socket
audit(1095188122.331:0): avc:  denied  { name_bind } for  pid=3050
exe=/usr/sbin/ntpd src=683 scontext=user_u:system_r:ntpd_t
tcontext=system_u:object_r:reserved_port_t tclass=tcp_socket
audit(1095188122.341:0): avc:  denied  { name_bind } for  pid=3050
exe=/usr/sbin/ntpd src=684 scontext=user_u:system_r:ntpd_t
tcontext=system_u:object_r:reserved_port_t tclass=tcp_socket


The mdadm error repeats periodically and interferes with my use of the
console.

Version-Release number of selected component (if applicable):
selinux-policy-targeted-1.17.14-1

How reproducible:
Always

Comment 1 Alexandre Oliva 2004-09-14 22:14:06 UTC
Yuck.  This problem causes a messed-up initrd.img to be created if
your root device happens to be on raid.

Comment 2 Colin Walters 2004-09-14 22:52:04 UTC
The mdadm bug is fixed by a patch I sent to selinux@tycho.  Not sure
about the ntpd one.

Comment 6 Daniel Walsh 2004-09-15 15:08:13 UTC
selinux-policy-targeted-1.17.16-2 should fix this problem.

Comment 7 Daniel Reed 2004-09-15 15:22:55 UTC
I upgraded to selinux-policy-targeted-1.17.16-2 and no longer receive
the ntpd error. (I have not received the mdadm error since Colin
patched my sources yesterday afternoon, and upgrading to 16-2 did not
cause the mdadm error to resurface.)

I found 16-2 in dist/fc3-HEAD and not dist/fc3, and I'm not sure if
that means this can be closed "RAWHIDE" or not.

Comment 8 Alexandre Oliva 2004-09-16 03:37:29 UTC
It made it to FC3-re0915.0, so it's certainly going to be in FC3test2
and probably tomorrow's rawhide.  Feel free to close it.


Note You need to log in before you can comment on or make changes to this bug.