Hide Forgot
Description of problem: Version-Release number of selected component (if applicable): selinux-policy-3.7.19-292.el6.noarch selinux-policy-targeted-3.7.19-292.el6.noarch How reproducible: * always Steps to Reproduce: 1. get a clean RHEL-6.8 machine (targeted policy is active) 2. try to run semanage even if it's not installed # semanage Command not found. Install package 'policycoreutils-python' to provide command 'semanage'? [N/y] # 3. skip the installation of the package Actual results (enforcing mode): ---- time->Wed Nov 23 06:24:42 2016 type=SYSCALL msg=audit(1479900282.454:212): arch=c000003e syscall=83 success=no exit=-13 a0=dbdf00 a1=1ed a2=2 a3=7fff61ab4a90 items=0 ppid=1702 pid=1703 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="console-kit-dae" exe="/usr/sbin/console-kit-daemon" subj=system_u:system_r:consolekit_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1479900282.454:212): avc: denied { create } for pid=1703 comm="console-kit-dae" name="ConsoleKit" scontext=system_u:system_r:consolekit_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_log_t:s0 tclass=dir ---- Actual results (permissive mode): ---- time->Wed Nov 23 06:27:02 2016 type=SYSCALL msg=audit(1479900422.521:214): arch=c000003e syscall=83 success=yes exit=0 a0=1a62f00 a1=1ed a2=2 a3=7fff77de50d0 items=0 ppid=1786 pid=1787 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="console-kit-dae" exe="/usr/sbin/console-kit-daemon" subj=system_u:system_r:consolekit_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1479900422.521:214): avc: denied { create } for pid=1787 comm="console-kit-dae" name="ConsoleKit" scontext=system_u:system_r:consolekit_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_log_t:s0 tclass=dir ---- Expected results: * no AVCs * /var/log/ConsoleKit directory is labeled correctly during its creation # ls -dZ /var/log/ConsoleKit drwxr-xr-x. root root system_u:object_r:var_log_t:s0 /var/log/ConsoleKit # ls -dZ /var/log/ConsoleKit/history -rw-r--r--. root root system_u:object_r:consolekit_log_t:s0 /var/log/ConsoleKit/history #
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHBA-2017-0627.html