Bug 238519 - AVC denied { signull } for setroubleshootd
AVC denied { signull } for setroubleshootd
Status: CLOSED CURRENTRELEASE
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
rawhide
All Linux
medium Severity high
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2007-04-30 20:47 EDT by Robert Scheck
Modified: 2007-11-30 17:12 EST (History)
1 user (show)

See Also:
Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2007-08-22 10:13:48 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:


Attachments (Terms of Use)

  None (edit)
Description Robert Scheck 2007-04-30 20:47:47 EDT
Description of problem:
type=AVC msg=audit(1177979939.505:177768): avc:  denied  { signull } for  
pid=15541 comm="setroubleshootd" scontext=user_u:system_r:setroubleshootd_t:s0 
tcontext=user_u:system_r:setroubleshootd_t:s0 tclass=process
type=SYSCALL msg=audit(1177979939.505:177768): arch=40000003 syscall=37 
success=yes exit=0 a0=3cb3 a1=0 a2=e1cbb4 a3=b65e50f8 items=0 ppid=1 pid=15541 
auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) 
comm="setroubleshootd" exe="/usr/bin/python" 
subj=user_u:system_r:setroubleshootd_t:s0 key=(null)

Version-Release number of selected component (if applicable):
selinux-policy-2.6.1-1
selinux-policy-targeted-2.6.1-1

How reproducible:
Everytime, just start setroubleshoot.

Actual results:
AVC denied message, setroubleshoot is exiting...

Expected results:
No AVC denied message, no quitting setroubleshoot.
Comment 1 Robert Scheck 2007-05-03 16:55:06 EDT
type=AVC msg=audit(1178136814.147:178768): avc:  denied  { signull } for  
pid=5868 comm="setroubleshootd" scontext=user_u:system_r:setroubleshootd_t:s0 
tcontext=user_u:system_r:unconfined_t:s0 tclass=process
type=SYSCALL msg=audit(1178136814.147:178768): arch=40000003 syscall=37 
success=yes exit=0 a0=361a a1=0 a2=1128bb4 a3=b6400188 items=0 ppid=1 pid=5868 
auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) 
comm="setroubleshootd" exe="/usr/bin/python" 
subj=user_u:system_r:setroublesootd_t:s0 key=(null)
Comment 2 Daniel Walsh 2007-05-04 09:35:23 EDT
How did you get this to happen?  
Comment 3 Robert Scheck 2007-05-04 09:53:01 EDT
I'm just starting setroubleshootd and waiting some time until it kills itself.
Comment 4 Daniel Walsh 2007-05-04 10:41:50 EDT
Fixed in selinux-policy-2.6.3-1.fc7
Comment 5 Robert Scheck 2007-05-04 14:09:14 EDT
Is 2.6.3-1 somewhere available during the merge?
Comment 6 Robert Scheck 2007-05-06 17:27:03 EDT
type=AVC msg=audit(1178387459.584:180684): avc:  denied  { signull } for  
pid=27007 comm="setroubleshootd" scontext=user_u:system_r:setroubleshootd_t:s0 
tcontext=user_u:system_r:rpm_t:s0 tclass=process
type=SYSCALL msg=audit(1178387459.584:180684): arch=40000003 syscall=37 
success=yes exit=0 a0=6895 a1=0 a2=ffebb4 a3=b513cbe0 items=0 ppid=1 pid=27007 
auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) 
comm="setroubleshootd" exe="/usr/bin/python" 
subj=user_u:system_r:setroubleshootd_t:s0 key=(null)"
Comment 7 Robert Scheck 2007-05-06 17:27:35 EDT
Daniel, looks like setroubleshootd has problems with signull?!
Comment 8 Robert Scheck 2007-05-27 06:06:46 EDT
NO! This bug is not fixed in selinux-policy-targeted-2.6.4-8:

type=AVC msg=audit(1180177580.521:188757): avc:  denied  { signull } for  
pid=16328 comm="setroubleshootd" scontext=user_u:system_r:setroubleshootd_t:s0 
tcontext=user_u:system_r:unconfined_t:s0 tclass=process
type=SYSCALL msg=audit(1180177580.521:188757): arch=40000003 syscall=37 
success=yes exit=0 a0=4f19 a1=0 a2=10c8c14 a3=b524f008 items=0 ppid=1 
pid=16328 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=
(none) comm="setroubleshootd" exe="/usr/bin/python" 
subj=user_u:system_r:setroubleshootd_t:s0 key=(null)

See also comment #6 at this bug report.
Comment 9 Robert Scheck 2007-05-30 18:20:22 EDT
Ping?
Comment 10 Robert Scheck 2007-06-10 18:02:18 EDT
I'm assuming this bug isn't also fixed in selinux-policy-targeted-2.6.5-2
Comment 11 Daniel Walsh 2007-06-11 10:34:22 EDT
It should be.
Comment 12 Daniel Walsh 2007-06-11 10:36:07 EDT
selinux-policy-2.6.4-13 definitely has the fix.
Comment 13 Daniel Walsh 2007-08-22 10:13:48 EDT
Should be fixed in the current release

Note You need to log in before you can comment on or make changes to this bug.