Bug 213603 - avc denied for amanda
avc denied for amanda
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2006-11-02 03:24 EST by Patrick C. F. Ernzer
Modified: 2007-11-30 17:11 EST (History)
0 users

See Also:
Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2007-09-12 13:08:08 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
part of audit.log and syslog (4.51 KB, application/x-bzip2)
2006-11-07 06:14 EST, Patrick C. F. Ernzer
no flags Details

  None (edit)
Description Patrick C. F. Ernzer 2006-11-02 03:24:11 EST
shouldn't this be allowed:

avc: denied { name_bind } for comm='"amandad"' egid='6' euid='33'
exe='"/usr/lib/amanda/amandad"' exit='-13' fsgid='6' fsuid='33' gid='6'
items='0' pid='7178' scontext=system_u:system_r:amanda_t:s0 sgid='6'
subj='system_u:system_r:amanda_t:s0' suid='33' tclass='tcp_socket'
tcontext=system_u:object_r:reserved_port_t:s0 tty='(none)' uid='33'


Amanda server is an ancient Red Hat Linux Advanced Server release 2.1AS
(Pensacola) but I guess that does not matter in this case.
Comment 2 Daniel Walsh 2006-11-06 14:24:15 EST
Could you grab the AVC from /var/log/audit/audit.log.  Not sure which port this
is trying to listen on.

It should be handled by the current policy.
Comment 3 Patrick C. F. Ernzer 2006-11-07 06:14:36 EST
Created attachment 140551 [details]
part of audit.log and syslog

sure, here is the result of
# grep amanda /var/log/messages > /tmp/amanda-in-messages
# grep amanda /var/log/audit/audit.log > /tmp/amanda-in-audit=
# cd /tmp/
# tar cvjf logs-BZ213603.tar.bz2 amanda-in-*
Comment 4 Daniel Walsh 2006-11-10 17:23:34 EST
Fixed in selinux-policy-2.4.3-10
Comment 5 Daniel Walsh 2007-09-12 13:08:08 EDT
Moving modified bugs to closed

Note You need to log in before you can comment on or make changes to this bug.