Bug 524174 - setroubleshoot: SELinux is preventing consoletype (consoletype_t) "read write" socket (pppd_t).
Summary: setroubleshoot: SELinux is preventing consoletype (consoletype_t) "read ...
Keywords:
Status: CLOSED DUPLICATE of bug 531374
Alias: None
Product: Fedora
Classification: Fedora
Component: ppp
Version: 12
Hardware: i386
OS: Linux
low
medium
Target Milestone: ---
Assignee: Jiri Skala
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:d7bb82611d7...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-09-18 08:25 UTC by Hongwen Qiu
Modified: 2014-11-09 22:32 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2009-11-23 07:57:49 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Hongwen Qiu 2009-09-18 08:25:06 UTC
The following was filed automatically by setroubleshoot:

概述:

SELinux is preventing consoletype (consoletype_t) "read write" socket (pppd_t).

详细描述:

[SELinux is in permissive mode. This access was not denied.]

SELinux denied access requested by the consoletype command. It looks like this
is either a leaked descriptor or consoletype output was redirected to a file it
is not allowed to access. Leaks usually can be ignored since SELinux is just
closing the leak and reporting the error. The application does not use the
descriptor, so it will run properly. If this is a redirection, you will not get
output in the socket. You should generate a bugzilla on selinux-policy, and it
will get routed to the appropriate package. You can safely ignore this avc.

允许访问:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385)

附加信息:

源上下文                  system_u:system_r:consoletype_t:s0
目标上下文               system_u:system_r:pppd_t:s0
目标对象                  socket [ packet_socket ]
源                           consoletype
源路径                     /sbin/consoletype
端口                        <未知>
主机                        (removed)
源 RPM 软件包             initscripts-8.97-1
目标 RPM 软件包          
策略 RPM                    selinux-policy-3.6.26-8.fc12
启用 Selinux                True
策略类型                  targeted
启用 MLS                    True
Enforcing 模式              Permissive
插件名称                  leaks
主机名                     (removed)
平台                        Linux (removed)
                              2.6.31-0.125.4.2.rc5.git2.fc12.i686.PAE #1 SMP Tue
                              Aug 11 21:01:03 EDT 2009 i686 i686
警报计数                  2
第一个                     2009年08月29日 星期六 12时12分03秒
最后一个                  2009年08月29日 星期六 12时23分48秒
本地 ID                     9bc88fa7-f983-4e04-aa32-9051db13479e
行号                        

原始核查信息            

node=(removed) type=AVC msg=audit(1251519828.112:40826): avc:  denied  { read write } for  pid=2107 comm="consoletype" path="socket:[16007]" dev=sockfs ino=16007 scontext=system_u:system_r:consoletype_t:s0 tcontext=system_u:system_r:pppd_t:s0 tclass=packet_socket

node=(removed) type=SYSCALL msg=audit(1251519828.112:40826): arch=40000003 syscall=11 success=yes exit=0 a0=8e4a868 a1=8e4a8c8 a2=8e43460 a3=8e4a8c8 items=0 ppid=2106 pid=2107 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="consoletype" exe="/sbin/consoletype" subj=system_u:system_r:consoletype_t:s0 key=(null)


audit2allow suggests:

#============= consoletype_t ==============
allow consoletype_t pppd_t:packet_socket { read write };

Comment 1 Daniel Walsh 2009-09-18 12:05:28 UTC
pppd should not be leaking file descriptors.

It should close all sockets before execing helper apps.

fcntl(fd, F_SETFD, FD_CLOEXEC)

Comment 2 Jiri Skala 2009-11-12 14:45:54 UTC
Hi,
I can't reproduce AVC denial. I tried to make changes mentioned by Daniel.
Could you test it if there is some progress?
The scratch build is available in koji: 

http://koji.fedoraproject.org/koji/taskinfo?taskID=1796872

Thanks, regards

Jiri

Comment 3 Bug Zapper 2009-11-16 12:35:53 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 12 development cycle.
Changing version to '12'.

More information and reason for this action is here:
http://fedoraproject.org/wiki/BugZappers/HouseKeeping

Comment 4 Jiri Skala 2009-11-23 07:57:49 UTC

*** This bug has been marked as a duplicate of bug 531374 ***


Note You need to log in before you can comment on or make changes to this bug.