Bug 502190
| Summary: | SELinux is preventing perl (logwatch_t) "write" to ./services (etc_t). | ||||||
|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 5 | Reporter: | Jay Turner <jturner> | ||||
| Component: | dmraid | Assignee: | LVM and device-mapper development team <lvm-team> | ||||
| Status: | CLOSED DUPLICATE | QA Contact: | Cluster QE <mspqa-list> | ||||
| Severity: | high | Docs Contact: | |||||
| Priority: | medium | ||||||
| Version: | 5.4 | CC: | agk, dwysocha, heinzm, mbroz, prockai, srevivo, syeghiay | ||||
| Target Milestone: | rc | Keywords: | Regression | ||||
| Target Release: | --- | ||||||
| Hardware: | All | ||||||
| OS: | Linux | ||||||
| Whiteboard: | |||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||
| Doc Text: | Story Points: | --- | |||||
| Clone Of: | Environment: | ||||||
| Last Closed: | 2009-06-11 10:56:09 UTC | Type: | --- | ||||
| Regression: | --- | Mount Type: | --- | ||||
| Documentation: | --- | CRM: | |||||
| Verified Versions: | Category: | --- | |||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||
| Embargoed: | |||||||
| Attachments: |
|
||||||
|
Description
Jay Turner
2009-05-22 13:23:29 UTC
A bit more information. Getting the following as well: Permission denied at /etc/logwatch/scripts/services/dmeventd line 46. (In reply to comment #1) > A bit more information. Getting the following as well: > > Permission denied at /etc/logwatch/scripts/services/dmeventd line 46. Indicating, that the script doesn't have proper credentials to open its log file "/etc/logwatch/scripts/services/dmeventd_syslogpattern.txt", which didn't change name and wasn't an issue in the 5.3 version. I assume an SELinux policy change ? selinux-policy last changed on my system May 15th. These denials began on May 22nd (the first showing up at 07:24EDT.) And indeed now that I'm looking at it, appears that dmraid-events wasn't updated until 09:50EDT.
rpm.log attached (output of 'rpm -qa --last')
audit2allow and audit2why output:
# cat /var/log/audit/audit.log | audit2allow
#============= logwatch_t ==============
allow logwatch_t etc_t:dir write;
allow logwatch_t etc_t:file write;
[root@dyno ~]# audit2why < /var/log/audit/audit.log
type=AVC msg=audit(1242991478.645:225): avc: denied { write } for pid=5773 comm="perl" name="services" dev=dm-3 ino=3273683 scontext=system_u:system_r:logwatch_t:s0-s0:c0.c1023 tcontext=system_u:object_r:etc_t:s0 tclass=dir
Was caused by:
Missing or disabled TE allow rule.
Allow rules may exist but be disabled by boolean settings; check boolean settings.
You can see the necessary allow rules by running audit2allow with this audit message as input.
type=AVC msg=audit(1243338724.872:29): avc: denied { write } for pid=6407 comm="perl" name="dmeventd_syslogpattern.txt" dev=dm-3 ino=3273725 scontext=system_u:system_r:logwatch_t:s0-s0:c0.c1023 tcontext=user_u:object_r:etc_t:s0 tclass=file
Was caused by:
Missing or disabled TE allow rule.
Allow rules may exist but be disabled by boolean settings; check boolean settings.
You can see the necessary allow rules by running audit2allow with this audit message as input.
Created attachment 345457 [details]
'rpm -qa --last' output
I've done a relabel of the filesystem and have received several more of these denials. We really need to get to the bottom of this for 5.4. *** This bug has been marked as a duplicate of bug 475562 *** |