Bug 243453 - audio-entropyd AVC denials
Summary: audio-entropyd AVC denials
Keywords:
Status: CLOSED NEXTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: audio-entropyd
Version: 7
Hardware: i386
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tom "spot" Callaway
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2007-06-08 19:33 UTC by Jerry James
Modified: 2007-11-30 22:12 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2007-07-10 16:17:56 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Jerry James 2007-06-08 19:33:28 UTC
Description of problem:
On my next reboot after installing audio-entropyd onto a fresh F7 install, I got
the following AVC denials (with SELinux in permissive mode):

avc: denied { read, write } for comm="audio-entropyd" dev=tmpfs egid=0 euid=0
exe="/usr/sbin/audio-entropyd" exit=4 fsgid=0 fsuid=0 gid=0 items=0
name="random" pid=2592 scontext=system_u:system_r:entropyd_t:s0 sgid=0
subj=system_u:system_r:entropyd_t:s0 suid=0 tclass=chr_file
tcontext=system_u:object_r:random_device_t:s0 tty=(none) uid=0 

avc: denied { ioctl } for comm="audio-entropyd" dev=tmpfs egid=0 euid=0
exe="/usr/sbin/audio-entropyd" exit=0 fsgid=0 fsuid=0 gid=0 items=0
name="random" path="/dev/random" pid=2592
scontext=system_u:system_r:entropyd_t:s0 sgid=0
subj=system_u:system_r:entropyd_t:s0 suid=0 tclass=chr_file
tcontext=system_u:object_r:random_device_t:s0 tty=(none) uid=0 

avc: denied { dac_override } for comm="audio-entropyd" egid=0 euid=0
exe="/usr/sbin/audio-entropyd" exit=5 fsgid=0 fsuid=0 gid=0 items=0 pid=2592
scontext=system_u:system_r:entropyd_t:s0 sgid=0
subj=system_u:system_r:entropyd_t:s0 suid=0 tclass=capability
tcontext=system_u:system_r:entropyd_t:s0 tty=(none) uid=0 

Version-Release number of selected component (if applicable):
audio-entropyd-1.0.0-2.fc7

How reproducible:
Don't know.

Steps to Reproduce:
1. Install audio-entropyd
2. Reboot

Actual results:
The AVC denials described above are issued.

Expected results:
No AVC denials.

Additional info:

Comment 1 Tom "spot" Callaway 2007-07-10 16:17:56 UTC
The selinux-policy-2.6.4-25.fc7 package has an audioentropy module that seems to
work for me in resolving these AVC denials.

Please reopen if it doesn't resolve them.


Note You need to log in before you can comment on or make changes to this bug.