Bug 1626849 - sosreport: SELinux map denials for dogtag-ipa-renew*
Summary: sosreport: SELinux map denials for dogtag-ipa-renew*
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 29
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-09-09 18:12 UTC by Sanne Raymaekers
Modified: 2018-10-24 06:21 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2018-10-24 06:21:46 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
full journal (1.44 MB, text/x-vhdl)
2018-09-09 18:12 UTC, Sanne Raymaekers
no flags Details

Description Sanne Raymaekers 2018-09-09 18:12:03 UTC
Created attachment 1481891 [details]
full journal

Description of problem:


audit: type=1400 audit(1536511958.363:567): avc:  denied  { map } for  pid=4338 comm="dogtag-ipa-rene" path=2F72756E2F636572746D6F6E6765722F6666694D684B4C3730202864656C6574656429 dev="tmpfs" ino=39810 scontext=system_u:system_r:certmonger_t:s0 tcontext=system_u:object_r:certmonger_var_run_t:s0 tclass=file permissive=0
audit: type=1400 audit(1536511958.377:570): avc:  denied  { write } for  pid=4338 comm="dogtag-ipa-rene" name="/" dev="tmpfs" ino=11587 scontext=system_u:system_r:certmonger_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=dir permissive=0

Version-Release number of selected component (if applicable):
sos-3.6-4.fc29.noarch
selinux-policy-3.14.2-32.fc29.noarch

Happens sporadically in cockpit integration tests.

Comment 1 Martin Pitt 2018-10-24 06:21:46 UTC
This got fixed now, see bug 1624930 (internal).


Note You need to log in before you can comment on or make changes to this bug.