Bug 481459 - various SELinux-related warnings on update
Summary: various SELinux-related warnings on update
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: policycoreutils
Version: rawhide
Hardware: All
OS: Linux
low
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-01-25 07:22 UTC by Christopher Beland
Modified: 2009-02-02 13:16 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-02-02 13:16:48 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
excerpts from /var/log/messages during and after "yum update" (13.93 KB, text/plain)
2009-01-25 07:22 UTC, Christopher Beland
no flags Details
/etc/selinux/restorecond.conf (133 bytes, text/plain)
2009-01-30 14:37 UTC, Christopher Beland
no flags Details
excerpt from /var/log/messages (15.20 KB, text/plain)
2009-01-30 14:42 UTC, Christopher Beland
no flags Details

Description Christopher Beland 2009-01-25 07:22:06 UTC
Created attachment 329927 [details]
excerpts from /var/log/messages during and after "yum update"

During my latest "yum update" I got a number of warning or error messages which appear to have something to do with various SELinux components, including:

* udevd[9454]: specified group 'dialout' unknown
* restorecond: Will not restore a file with more than one hard link (/home/beland/.Xauthority-c) Invalid argument
* restorecond: Unable to watch (/home/beland/.mozilla/plugins/libflashplayer.so) No such file or directory
* dbus: Can't send to audit system: USER_AVC avc: ...
* Various "avc:  denied"

Note that auditd is not running due to bug 476380.

I've included my system log so you can see these in context; at least some of them seem to be related.  I don't know what's giving the system the impression that /home/beland/.mozilla/plugins/libflashplayer.so should exist; it would be nice if the error message was more informative about that.

After the update, I now have installed:

libselinux-2.0.77-2.fc11.i386
libselinux-2.0.77-2.fc11.x86_64
libselinux-debuginfo-2.0.77-2.fc11.x86_64
libselinux-python-2.0.77-2.fc11.x86_64
libselinux-utils-2.0.77-2.fc11.x86_64
selinux-policy-3.6.3-8.fc11.noarch
selinux-policy-targeted-3.6.3-8.fc11.noarch
checkpolicy-2.0.16-3.fc10.x86_64
checkpolicy-debuginfo-2.0.16-3.fc10.x86_64
policycoreutils-2.0.61-6.fc11.x86_64
policycoreutils-debuginfo-2.0.61-6.fc11.x86_64
policycoreutils-gui-2.0.61-6.fc11.x86_64
policycoreutils-python-2.0.61-6.fc11.x86_64
udev-136-2.fc11.x86_64

Comment 1 Daniel Walsh 2009-01-26 18:18:36 UTC
The rpm/groupadd bug has been reported separarely,   The dbus bug should be reported to dbus.

restorecond, seems to be complaining about the contents of your homedir?  What is .Xautority?  Is this a hardlink somewhere else?

Comment 2 Christopher Beland 2009-01-29 05:41:46 UTC
I cannot find the udev "specified group 'dialout' unknown" bug in bugzilla.  Unless this is caused by bug 480795?

Comment 3 Christopher Beland 2009-01-29 06:39:56 UTC
Ah, I think the udev message is due to bug 480762?

dbus issue reported separately at bug 482977.

At least at the moment, stat reports that there is only one hard link to /home/beland/.Xauthority, which looks like a normal file.  But I think it's overwritten every time I log in.

Comment 4 Daniel Walsh 2009-01-30 13:33:26 UTC
Please attach your restorecond.conf file

Comment 5 Christopher Beland 2009-01-30 14:37:40 UTC
Created attachment 330470 [details]
/etc/selinux/restorecond.conf

~/.mozilla/plugins/libflashplayer.so is the last line, so I suppose that explains where *that* is coming from.

Comment 6 Christopher Beland 2009-01-30 14:42:45 UTC
Created attachment 330471 [details]
excerpt from /var/log/messages

I noticed similar restorecond messages in /var/log/messages today; attached is an excerpt in case the additional context is helpful.

Comment 7 Daniel Walsh 2009-02-02 13:16:48 UTC
Fixed in policycoreutils-2.0.61-7.fc11


Note You need to log in before you can comment on or make changes to this bug.