Bug 208900 - Several avc's from various systems reported by setroubleshoot.
Several avc's from various systems reported by setroubleshoot.
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2006-10-02 11:36 EDT by Tom Diehl
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2006-12-07 18:01:02 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Tom Diehl 2006-10-02 11:36:25 EDT
Description of problem:Setroubleshoot reports several AVC's

Version-Release number of selected component (if applicable):
(tigger pts4) $ rpm -qa | grep selinux
(tigger pts4) $

How reproducible:

Most likely always but I am not 100% sure.

Steps to Reproduce:
1. Boot machine, enable setroubleshoot and wait.
Actual results:
AVC messages

Expected results:
No AVC messages.

Additional info:
Here are the avc messages reported by setroubleshootd.
If you need more info let me know.

Raw Audit Messages
denied { execute } for comm='"ld-linux.so.2"' dev='dm-3' egid='0' euid='0'
exe='"/lib/ld-2.4.90.so"' exit='-13' fsgid='0' fsuid='0' gid='0' items='0'
name='"spamc"' path='"/usr/bin/spamc"' pid='10835'
scontext=system_u:system_r:prelink_t:s0-s0:c0.c1023 sgid='0'
subj='system_u:system_r:prelink_t:s0-s0:c0.c1023' suid='0' tclass='file'
tcontext=system_u:object_r:spamc_exec_t:s0 tty='(none)' uid='0' 

denied { connectto } for comm='"python"' egid='0' euid='0'
exe='"/usr/bin/python"' exit='-13' fsgid='0' fsuid='0' gid='0' items='0'
name='"cups.sock"' path='"/var/run/cups/cups.sock"' pid='2003'
scontext=system_u:system_r:cupsd_config_t:s0 sgid='0'
subj='system_u:system_r:cupsd_config_t:s0' suid='0' tclass='unix_stream_socket'
tcontext=system_u:system_r:initrc_t:s0-s0:c0.c1023 tty='(none)' uid='0' 

denied { read, write } for comm='"hal-storage-cle"' dev='dm-0' egid='0' euid='0'
exe='"/usr/libexec/hal-storage-cleanup-all-mountpoints"' exit='-13' fsgid='0'
fsuid='0' gid='0' items='0' name='".hal-mtab-lock"' pid='1980'
scontext=system_u:system_r:hald_t:s0 sgid='0' subj='system_u:system_r:hald_t:s0'
suid='0' tclass='file' tcontext=system_u:object_r:default_t:s0 tty='(none)' uid='0'

denied { search } for comm='"smb"' dev='dm-0' egid='7' euid='4'
exe='"/usr/bin/smbspool"' exit='-13' fsgid='7' fsuid='4' gid='7' items='0'
name='"samba"' pid='2887' scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023
sgid='7' subj='system_u:system_r:cupsd_t:s0-s0:c0.c1023' suid='4' tclass='dir'
tcontext=system_u:object_r:samba_etc_t:s0 tty='(none)' uid='4'

The system is rawhide updated to 01 Oct 2006.

I am having issues printing (need more time to investigate exactly why), I do
not have samba configured but it is installed.

Sorry if these are dups. I looked at the selinux bugs but did not see anything
that matched. I also relabeled the system before these messages showed up.

WOuld you prefer screen shots of setroubleshoor or are the AVC's sufficient??
Comment 1 Daniel Walsh 2006-10-04 15:01:46 EDT
Fixed in selinux-policy-2.3.18-2

Note You need to log in before you can comment on or make changes to this bug.