Bug 386481 - avc messaged caused by autofs enhancements for RHEL 5 update 2
avc messaged caused by autofs enhancements for RHEL 5 update 2
Product: Red Hat Enterprise Linux 5
Classification: Red Hat
Component: selinux-policy (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Daniel Walsh
Depends On:
  Show dependency treegraph
Reported: 2007-11-16 03:51 EST by Ian Kent
Modified: 2008-05-21 12:06 EDT (History)
1 user (show)

See Also:
Fixed In Version: RHBA-2008-0465
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-05-21 12:06:08 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Example avc messages related to named autofs use of named pipes (28.80 KB, text/plain)
2007-11-16 03:55 EST, Ian Kent
no flags Details

  None (edit)
Description Ian Kent 2007-11-16 03:51:23 EST
Description of problem:
We are making several enhancements to autofs in RHEL 5 update 2.

One such enhancement is the ability to alter the debug logging
of automount managed mount points. This has been implemented
using a named pipe to communicate the log level changes
to the running daemon by invoking the daemon program with
an option specifying the change in log level.

Since autofs hasn't previously used these named pipes selinux
rightly informs us that "automount" isn't allowed to create,
read, write or unlink these named pipes.

Version-Release number of selected component (if applicable):
All revisions since RHEL autofs-5.0.1-0.rc2.56.

How reproducible:

Steps to Reproduce:
Start autofs with at least one configured mount point and
inspect the output in /var/log/messages.

Actual results:
avc messages informing us of the above issue.

Expected results:
No avc messages related to autofs use of the named pipes.

Additional info:
As was previously agreed, the proper place for named pipes
belonging to autofs are created within the /var/run directory.
Comment 1 Ian Kent 2007-11-16 03:55:11 EST
Created attachment 260931 [details]
Example avc messages related to named autofs use of named pipes
Comment 2 Daniel Walsh 2007-11-26 11:33:47 EST
Fixed in selinux-policy-2.4.6-107.el5
Comment 3 RHEL Product and Program Management 2007-11-26 11:34:28 EST
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release.  Product Management has requested
further review of this request by Red Hat Engineering, for potential
inclusion in a Red Hat Enterprise Linux Update release for currently deployed
products.  This request is not yet committed for inclusion in an Update
Comment 4 Jay Turner 2007-12-04 01:38:15 EST
QE ack for RHEL5.2.  See comment 0 for reproducer.
Comment 8 errata-xmlrpc 2008-05-21 12:06:08 EDT
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.


Note You need to log in before you can comment on or make changes to this bug.