Bug 213603 - avc denied for amanda
Summary: avc denied for amanda
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: 6
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-11-02 08:24 UTC by Patrick C. F. Ernzer
Modified: 2007-11-30 22:11 UTC (History)
0 users

Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-09-12 17:08:08 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
part of audit.log and syslog (4.51 KB, application/x-bzip2)
2006-11-07 11:14 UTC, Patrick C. F. Ernzer
no flags Details

Description Patrick C. F. Ernzer 2006-11-02 08:24:11 UTC
shouldn't this be allowed:

avc: denied { name_bind } for comm='"amandad"' egid='6' euid='33'
exe='"/usr/lib/amanda/amandad"' exit='-13' fsgid='6' fsuid='33' gid='6'
items='0' pid='7178' scontext=system_u:system_r:amanda_t:s0 sgid='6'
subj='system_u:system_r:amanda_t:s0' suid='33' tclass='tcp_socket'
tcontext=system_u:object_r:reserved_port_t:s0 tty='(none)' uid='33'

selinux-policy-2.4.1-3.fc6
amanda-client-2.5.0p2-4

Amanda server is an ancient Red Hat Linux Advanced Server release 2.1AS
(Pensacola) but I guess that does not matter in this case.
amanda-server-2.4.4p3-1.21as.1

Comment 2 Daniel Walsh 2006-11-06 19:24:15 UTC
Could you grab the AVC from /var/log/audit/audit.log.  Not sure which port this
is trying to listen on.

It should be handled by the current policy.

Comment 3 Patrick C. F. Ernzer 2006-11-07 11:14:36 UTC
Created attachment 140551 [details]
part of audit.log and syslog

sure, here is the result of
# grep amanda /var/log/messages > /tmp/amanda-in-messages
# grep amanda /var/log/audit/audit.log > /tmp/amanda-in-audit=
# cd /tmp/
# tar cvjf logs-BZ213603.tar.bz2 amanda-in-*

Comment 4 Daniel Walsh 2006-11-10 22:23:34 UTC
Fixed in selinux-policy-2.4.3-10

Comment 5 Daniel Walsh 2007-09-12 17:08:08 UTC
Moving modified bugs to closed



Note You need to log in before you can comment on or make changes to this bug.