This service will be undergoing maintenance at 00:00 UTC, 2017-10-23 It is expected to last about 30 minutes
Bug 509275 - SELinux preventing mcelog from reading /dev/urandom
SELinux preventing mcelog from reading /dev/urandom
Status: CLOSED NEXTRELEASE
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
11
x86_64 Linux
low Severity low
: ---
: ---
Assigned To: Miroslav Grepl
Ben Levenson
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2009-07-01 20:37 EDT by Jeffrey Bonggren
Modified: 2010-03-04 03:29 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2010-03-04 03:29:10 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Output From setroubleshoot (2.12 KB, text/plain)
2009-07-01 20:37 EDT, Jeffrey Bonggren
no flags Details

  None (edit)
Description Jeffrey Bonggren 2009-07-01 20:37:06 EDT
Created attachment 350227 [details]
Output From setroubleshoot

Ever since I upgraded from Fedora 10 to Fedora 11 (via preupgrade), I have been getting setroubleshoot alerts stating that "SELinux prevented mcelog from reading the urandom device".

This hasn't really been a big problem, but it is annoying.  I figure something is going wrong here, either in mcelog or in the SELinux configuration.

I don't understand why the mcelog would even need /dev/urandom.  Why does a logging program need randomness?

I am attaching the output from setroubleshoot.
Comment 1 Daniel Walsh 2009-07-06 13:49:16 EDT
Miroslav, upstream rejected the current policy for mcelog saying it is different from dmesg and asked for policy written specifically for it as a cron job.  Could you do that to fix this bug?

Jeffrey, 

for now you can add this allow rule using

# grep avc /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp
Comment 2 Miroslav Grepl 2010-03-04 03:29:10 EST
The mcelog policy was added to the F12 selinux-policy.

Note You need to log in before you can comment on or make changes to this bug.