Bug 234776 - AVC errors by hal-addon-acpi
AVC errors by hal-addon-acpi
Status: CLOSED NOTABUG
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
6
All Linux
medium Severity medium
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2007-04-01 17:49 EDT by Gérard Milmeister
Modified: 2007-11-30 17:12 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-04-05 13:47:26 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Gérard Milmeister 2007-04-01 17:49:45 EDT
I get the following errors on my notebook with targeted policy enabled:

Apr  1 23:47:53 kodaly kernel: audit(1175464073.509:149): avc:  denied  {
connectto } for  pid=4294 comm="hald-addon-acpi" name="acpid.socket"
scontext=user_u:system_r:hald_t:s0 tcontext=system_u:system_r:initrc_t:s0
tclass=unix_stream_socket

I used restorecon to reset the labeling of the files in /var, but the problem is
still present. The message appear about every 5 seconds.
Comment 1 Daniel Walsh 2007-04-02 13:41:25 EDT
apmd must not be running in the write context on this machine.

On my machine I have the following:

# ps -eZ | grep apmd
system_u:system_r:apmd_t         2480 ?        00:00:00 acpid

ls -lZ /var/run/acpid.socket 
srw-rw-rw-  root root system_u:object_r:apmd_var_run_t /var/run/acpid.socket

# ls -lZ /usr/sbin/acpid
-rwxr-x---  root root system_u:object_r:apmd_exec_t    /usr/sbin/acpid
Comment 2 Gérard Milmeister 2007-04-02 13:50:27 EDT
It's acpid, not apmd. Here is what I got:

$ps -eZ | grep acpid 
system_u:system_r:kernel_t         62 ?        00:00:02 kacpid
user_u:system_r:initrc_t         7166 ?        00:00:00 acpid

$ls -lZ /var/run/acpid.socket 
srw-rw-rw-  root root user_u:object_r:var_run_t        /var/run/acpid.socket=

$ls -lZ /usr/sbin/acpid       
-rwxr-x---  root root system_u:object_r:apmd_exec_t    /usr/sbin/acpid*
Comment 3 Gérard Milmeister 2007-04-02 14:02:44 EDT
Also, starting acpid using /etc/init.d/acpid always sets the type of
acpid.socket to var_run_t, even if I previously restored it to apmd_var_run_t.
Comment 4 Daniel Walsh 2007-04-02 14:12:17 EDT
getsebool -a | grep apm

Did you disable transition on acpid?

Comment 5 Gérard Milmeister 2007-04-02 14:41:39 EDT
Yes it was disabled. I enabled it again, and now everything seems to be as it
should. I don't know how it got changed at all.

Note You need to log in before you can comment on or make changes to this bug.