Today's rawhide; when doing a service iscsid restart Raw Audit Messages: host=f9 type=AVC msg=audit(1208254723.300:33): avc: denied { signal } for pid=1467 comm="iscsid" scontext=system_u:system_r:iscsid_t:s0 tcontext=system_u:system_r:iscsid_t:s0 tclass=process host=f9 type=SYSCALL msg=audit(1208254723.300:33): arch=40000003 syscall=37 success=no exit=-13 a0=5ba a1=f a2=5ba a3=0 items=0 ppid=1 pid=1467 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="iscsid" exe="/sbin/iscsid" subj=system_u:system_r:iscsid_t:s0 key=(null)
My fix: --- serefpolicy-3.3.1/policy/modules/system/iscsi.te 2008-04-15 13:29:59.000000000 +0200 +++ serefpolicy-3.3.1.myFix/policy/modules/system/iscsi.te 2008-04-15 13:31:32.000000000 +0200 @@ -29,7 +29,7 @@ # allow iscsid_t self:capability { dac_override ipc_lock net_admin sys_nice sys_resource }; -allow iscsid_t self:process { setrlimit setsched }; +allow iscsid_t self:process { setrlimit setsched signal }; allow iscsid_t self:fifo_file { read write }; allow iscsid_t self:unix_stream_socket { create_stream_socket_perms connectto }; allow iscsid_t self:unix_dgram_socket create_socket_perms;
Correct. You can allow this for now by executing # audit2allow -M mypol -i /var/log/audit/audit.log # semodule -i mypol.pp Fixed in selinux-policy-3.3.1-36.fc9