Bug 394741 - selinux denying fifo creation
selinux denying fifo creation
Status: CLOSED CURRENTRELEASE
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
rawhide
All Linux
low Severity high
: ---
: ---
Assigned To: Daniel Walsh
Fedora Extras Quality Assurance
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2007-11-21 13:36 EST by Felix Bellaby
Modified: 2008-01-30 14:06 EST (History)
2 users (show)

See Also:
Fixed In Version: Current
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2008-01-30 14:06:37 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Felix Bellaby 2007-11-21 13:36:57 EST
Description of problem:


Version-Release number of selected component (if applicable):

autofs-5.0.2-18.src.rpm

How reproducible:

check audit.log on autofs startup.

Summary log:

SELinux is preventing /usr/sbin/automount (automount_t) "create" to (var_run_t).

Raw log:

avc: denied { create } for comm=automount egid=0 euid=0 exe=/usr/sbin/automount
exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name=autofs.fifo-net pid=10382
scontext=system_u:system_r:automount_t:s0 sgid=0
subj=system_u:system_r:automount_t:s0 suid=0 tclass=fifo_file
tcontext=system_u:object_r:var_run_t:s0 tty=(none) uid=0 

Probably need to update the selinux permissions to allow creation of a fifo
wherever automounter is trying to create one.
Comment 1 Ian Kent 2007-11-25 23:48:54 EST
The failure to create the fifos just means that changing
debug logging level, on the fly, from the command line won't
be available so autofs should continue to function normally.

This update is also waiting in F8 testing.

Ian
Comment 2 Daniel Walsh 2007-11-26 11:23:32 EST
Fixed in selinux-policy-3.0.8-58.fc8

And Fixed in selinux-policy-3.1.2-1.fc9
Comment 3 Daniel Walsh 2008-01-30 14:06:37 EST
Bulk closing a old selinux policy bugs that were in the modified state.  If the
bug is still not fixed.  Please reopen.

Note You need to log in before you can comment on or make changes to this bug.