Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 152637 - /sbin/ip gets denied
/sbin/ip gets denied
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
i686 Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Depends On:
  Show dependency treegraph
Reported: 2005-03-30 17:09 EST by Florin Andrei
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-03-30 20:28:57 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Florin Andrei 2005-03-30 17:09:16 EST
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.6) Gecko/20050323 Firefox/1.0.2 Fedora/1.0.2-1.3.1

Description of problem:
Minimal FC4t1 install, all package groups de-selected, then i re-selected Development and Legacy Devel.
SELinux is in warning mode.

When booting up the system, i noticed this message:

Mar 30 14:02:17 ergo kernel: audit(1112220124.115:0): avc:  denied  { read } for  pid=1238 exe=/sbin/ip path=/init dev=rootfs ino=11 scontext=user_u:system_r:ifconfig_t tcontext=system_u:object_r:root_t tclass=file

Also, if i add "*.* /dev/tty12" in syslog.conf then switch to Alt-F12 and reboot the system, i believe i saw a similar message while the system is going down (init 6). That message does not show up in the syslog files, i don't know why. I could remember wrong, though.

If SELinux is configured in Force mode, a whole lot more messages like that are displayed, not just one.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1.see above

Additional info:
Comment 1 Daniel Walsh 2005-03-30 17:16:04 EST
Fixed in selinux-policy-targeted-1.23.5-1
Comment 2 Florin Andrei 2005-03-30 17:27:50 EST
Ok, i did a "yum update selinux-policy-targeted" and the bug is gone.
# rpm -q selinux-policy-targeted

However, when doing the update, i got this message:

warning: /etc/selinux/targeted/booleans saved as

Is that something i should worry about?

Also, how about these messages? Are they normal?

/sbin/restorecon reset context
/sbin/restorecon reset context
/sbin/restorecon reset context
Comment 3 Daniel Walsh 2005-03-30 20:28:57 EST
No we have changed the way we handle booleans, we now use booleans.local for
local customization.  

Hostname policy was removed because it was providing no benefit and causing
problems.  ssh_keysign_exec_t is a new policy, Not sure where the ulogd problem
came from, looks like someone moved a file from /tmp.

So these are normal.

Note You need to log in before you can comment on or make changes to this bug.