Bug 440189 - Current avc Denials during rawhide startup
Summary: Current avc Denials during rawhide startup
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: i686
OS: Linux
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
Depends On:
TreeView+ depends on / blocked
Reported: 2008-04-02 06:09 UTC by dex
Modified: 2008-05-02 20:12 UTC (History)
1 user (show)

Clone Of:
Last Closed: 2008-05-02 20:12:38 UTC

Attachments (Terms of Use)
dmesg (44.96 KB, text/plain)
2008-04-02 06:09 UTC, dex
no flags Details

Description dex 2008-04-02 06:09:21 UTC
Description of problem:
I'm Currently seeing these denials during startup on this rawhide system

Version-Release number of selected component (if applicable):

How reproducible:
start system

Steps to Reproduce:
1. start system
Actual results:

Expected results:
no denials

Additional info:

please see attached dmesg

Comment 1 dex 2008-04-02 06:09:21 UTC
Created attachment 300013 [details]

Comment 2 Daniel Walsh 2008-04-06 10:33:03 UTC
This looks like /sbin/hwclock does not have the correct label on it?

ls -lZ /sbin/hwclock

I am also not seeing these errors in the latest -28 policy.  Please make sure
there is only one policy file in /etc/selinux/targeted/policy

Remove the lower.

Comment 3 dex 2008-04-06 17:30:41 UTC
ls -lZ /sbin/hwclock
-rwxr-xr-x  root root system_u:object_r:hwclock_exec_t:s0 /sbin/hwclock

looks ok to my untrained eye.

Also no change with -28 same set of avc's after a relabel :-(

Comment 4 Daniel Walsh 2008-04-08 03:13:46 UTC
udev is supposed to be transitioning to hwclock_t

Are you sure udev is executing /sbin/hwclock?

Is /usr/sbin/hwclock a symlink?

Comment 5 dex 2008-04-08 21:49:22 UTC
(In reply to comment #4)
> udev is supposed to be transitioning to hwclock_t
> Are you sure udev is executing /sbin/hwclock?
How can I verify this, 

> Is /usr/sbin/hwclock a symlink?
lrwxrwxrwx  root root system_u:object_r:bin_t:s0       /usr/sbin/hwclock
-> ../../sbin/hwclock

policy -29

Comment 6 Daniel Walsh 2008-04-09 12:33:56 UTC
# yum install setools

# sesearch --allow | grep udev | grep hwclock
   allow udev_t hwclock_t : process transition ; 
   allow hwclock_t udev_t : process sigchld ; 
   allow hwclock_t udev_t : fd use ; 
   allow hwclock_t udev_t : fifo_file { ioctl read write getattr lock append }; 
   allow udev_t hwclock_exec_t : file { read getattr execute }; 
   allow hwclock_t udev_tbl_t : file { ioctl read getattr lock }; 

Also verify that there is only one policy file in

If there are more then one, please delete all but the greatest.

Note You need to log in before you can comment on or make changes to this bug.