Bug 151930 - avc: denied { getattr } for pid=2388 exe=/bin/mktemp path=/tmp dev=tmpfs ino=5312 scontext=user_u:system_r:dhcpc_t tcontext=user_u:object_r:tmpfs_t tclass=dir
avc: denied { getattr } for pid=2388 exe=/bin/mktemp path=/tmp dev=tmpfs i...
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
rawhide
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2005-03-23 12:35 EST by Orion Poplawski
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2005-04-07 12:22:17 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Add restorcon patch (425 bytes, patch)
2005-03-24 16:38 EST, Daniel Walsh
no flags Details | Diff

  None (edit)
Description Orion Poplawski 2005-03-23 12:35:42 EST
Description of problem:

Get the following audit on a freshly installed rawhide system:

avc:  denied  { getattr } for  pid=2388 exe=/bin/mktemp path=/tmp dev=tmpfs
ino=5312 scontext=user_u:system_r:dhcpc_t tcontext=user_u:object_r:tmpfs_t
tclass=dir

appears to prevent dhcp from setting /etc/resolv.conf properly.  

/tmp is a tmpfs filesystem


Version-Release number of selected component (if applicable):
selinux-policy-targeted-1.23.3-2.noarch.
Comment 1 Daniel Walsh 2005-03-24 16:38:38 EST
Created attachment 112338 [details]
Add restorcon patch
Comment 2 Daniel Walsh 2005-03-24 16:39:39 EST
Could you apply the above patch to /etc/rc.d/rc.sysinit 
and see if this fixes your problem
Comment 3 Orion Poplawski 2005-04-07 12:22:17 EDT
Did not see this with a fresh install from today's rawhide.  rc.sysinit does not
appear to have this patch, so apparently it's not necessary anymore?

/tmp is labeled as tmp_t:

drwxrwxrwt  root     root     system_u:object_r:tmp_t          .

Note You need to log in before you can comment on or make changes to this bug.