Bug 514543 - SELinux, denials for oracle
Summary: SELinux, denials for oracle
Keywords:
Status: CLOSED DUPLICATE of bug 500328
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Server
Version: 530
Hardware: All
OS: Linux
urgent
urgent
Target Milestone: ---
Assignee: Jan Pazdziora
QA Contact: wes hayutin
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-07-29 15:39 UTC by wes hayutin
Modified: 2009-07-30 15:15 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2009-07-30 15:05:14 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
spacewalk-debug (16.89 MB, application/octet-stream)
2009-07-29 15:39 UTC, wes hayutin
no flags Details

Description wes hayutin 2009-07-29 15:39:00 UTC
Created attachment 355573 [details]
spacewalk-debug

Description of problem:
7/24 iso in stage
Not sure if there is any specific recreate here.
I thought it was important to report the denials.


type=AVC msg=audit(1248769419.304:1375): avc:  denied  { search } for  pid=9273 comm="oracle" name="19606" dev=proc ino=1284898818 scontext=root:system_r:oracle_db_t:s0 tcontext=root:system_r:unconfined_t:s0-s0:c0.c1023 tclass=dir
type=AVC msg=audit(1248769419.308:1376): avc:  denied  { search } for  pid=9273 comm="oracle" name="19608" dev=proc ino=1285029890 scontext=root:system_r:oracle_db_t:s0 tcontext=root:system_r:unconfined_t:s0-s0:c0.c1023 tclass=dir
type=AVC msg=audit(1248769479.341:1377): avc:  denied  { search } for  pid=9273 comm="oracle" name="19606" dev=proc ino=1284898818 scontext=root:system_r:oracle_db_t:s0 tcontext=root:system_r:unconfined_t:s0-s0:c0.c1023 tclass=dir
type=AVC msg=audit(1248769479.345:1378): avc:  denied  { search } for  pid=9273 comm="oracle" name="19608" dev=proc ino=1285029890 scontext=root:system_r:oracle_db_t:s0 tcontext=root:system_r:unconfined_t:s0-s0:c0.c1023 tclass=dir
type=AVC msg=audit(1248769488.351:1379): avc:  denied  { search } for  pid=9273 comm="oracle" name="19608" dev=proc ino=1285029890 scontext=root:system_r:oracle_db_t:s0 tcontext=root:system_r:unconfined_t:s0-s0:c0.c1023 tclass=dir

Comment 2 Jan Pazdziora 2009-07-30 15:05:14 UTC

*** This bug has been marked as a duplicate of bug 500328 ***

Comment 3 Jan Pazdziora 2009-07-30 15:09:38 UTC
This looks like another crontab-time /proc searching example. We don't know what the cause is. The AVCs seem to come from Enforcing machine, we'd need output from Permissive to get the complete picture anyway.

Feel free to reopen if you think this is not a dupe of 500328.


Note You need to log in before you can comment on or make changes to this bug.