Bug 440189 - Current avc Denials during rawhide startup
Current avc Denials during rawhide startup
Product: Fedora
Classification: Fedora
Component: selinux-policy (Show other bugs)
i686 Linux
low Severity low
: ---
: ---
Assigned To: Daniel Walsh
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2008-04-02 02:09 EDT by dex
Modified: 2008-05-02 16:12 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-05-02 16:12:38 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
dmesg (44.96 KB, text/plain)
2008-04-02 02:09 EDT, dex
no flags Details

  None (edit)
Description dex 2008-04-02 02:09:21 EDT
Description of problem:
I'm Currently seeing these denials during startup on this rawhide system

Version-Release number of selected component (if applicable):

How reproducible:
start system

Steps to Reproduce:
1. start system
Actual results:

Expected results:
no denials

Additional info:

please see attached dmesg
Comment 1 dex 2008-04-02 02:09:21 EDT
Created attachment 300013 [details]
Comment 2 Daniel Walsh 2008-04-06 06:33:03 EDT
This looks like /sbin/hwclock does not have the correct label on it?

ls -lZ /sbin/hwclock

I am also not seeing these errors in the latest -28 policy.  Please make sure
there is only one policy file in /etc/selinux/targeted/policy

Remove the lower.
Comment 3 dex 2008-04-06 13:30:41 EDT
ls -lZ /sbin/hwclock
-rwxr-xr-x  root root system_u:object_r:hwclock_exec_t:s0 /sbin/hwclock

looks ok to my untrained eye.

Also no change with -28 same set of avc's after a relabel :-(
Comment 4 Daniel Walsh 2008-04-07 23:13:46 EDT
udev is supposed to be transitioning to hwclock_t

Are you sure udev is executing /sbin/hwclock?

Is /usr/sbin/hwclock a symlink?
Comment 5 dex 2008-04-08 17:49:22 EDT
(In reply to comment #4)
> udev is supposed to be transitioning to hwclock_t
> Are you sure udev is executing /sbin/hwclock?
How can I verify this, 

> Is /usr/sbin/hwclock a symlink?
lrwxrwxrwx  root root system_u:object_r:bin_t:s0       /usr/sbin/hwclock
-> ../../sbin/hwclock

policy -29
Comment 6 Daniel Walsh 2008-04-09 08:33:56 EDT
# yum install setools

# sesearch --allow | grep udev | grep hwclock
   allow udev_t hwclock_t : process transition ; 
   allow hwclock_t udev_t : process sigchld ; 
   allow hwclock_t udev_t : fd use ; 
   allow hwclock_t udev_t : fifo_file { ioctl read write getattr lock append }; 
   allow udev_t hwclock_exec_t : file { read getattr execute }; 
   allow hwclock_t udev_tbl_t : file { ioctl read getattr lock }; 

Also verify that there is only one policy file in

If there are more then one, please delete all but the greatest.

Note You need to log in before you can comment on or make changes to this bug.