Fedora Account System
Red Hat Associate
Red Hat Customer
The following was filed automatically by setroubleshoot: 概述: SELinux is preventing consoletype (consoletype_t) "read write" socket (pppd_t). 详细描述: [SELinux is in permissive mode. This access was not denied.] SELinux denied access requested by the consoletype command. It looks like this is either a leaked descriptor or consoletype output was redirected to a file it is not allowed to access. Leaks usually can be ignored since SELinux is just closing the leak and reporting the error. The application does not use the descriptor, so it will run properly. If this is a redirection, you will not get output in the socket. You should generate a bugzilla on selinux-policy, and it will get routed to the appropriate package. You can safely ignore this avc. 允许访问: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) 附加信息: 源上下文 system_u:system_r:consoletype_t:s0 目标上下文 system_u:system_r:pppd_t:s0 目标对象 socket [ packet_socket ] 源 consoletype 源路径 /sbin/consoletype 端口 <未知> 主机 (removed) 源 RPM 软件包 initscripts-8.97-1 目标 RPM 软件包 策略 RPM selinux-policy-3.6.26-8.fc12 启用 Selinux True 策略类型 targeted 启用 MLS True Enforcing 模式 Permissive 插件名称 leaks 主机名 (removed) 平台 Linux (removed) 2.6.31-0.125.4.2.rc5.git2.fc12.i686.PAE #1 SMP Tue Aug 11 21:01:03 EDT 2009 i686 i686 警报计数 2 第一个 2009年08月29日 星期六 12时12分03秒 最后一个 2009年08月29日 星期六 12时23分48秒 本地 ID 9bc88fa7-f983-4e04-aa32-9051db13479e 行号 原始核查信息 node=(removed) type=AVC msg=audit(1251519828.112:40826): avc: denied { read write } for pid=2107 comm="consoletype" path="socket:[16007]" dev=sockfs ino=16007 scontext=system_u:system_r:consoletype_t:s0 tcontext=system_u:system_r:pppd_t:s0 tclass=packet_socket node=(removed) type=SYSCALL msg=audit(1251519828.112:40826): arch=40000003 syscall=11 success=yes exit=0 a0=8e4a868 a1=8e4a8c8 a2=8e43460 a3=8e4a8c8 items=0 ppid=2106 pid=2107 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="consoletype" exe="/sbin/consoletype" subj=system_u:system_r:consoletype_t:s0 key=(null) audit2allow suggests: #============= consoletype_t ============== allow consoletype_t pppd_t:packet_socket { read write };
pppd should not be leaking file descriptors. It should close all sockets before execing helper apps. fcntl(fd, F_SETFD, FD_CLOEXEC)
Hi, I can't reproduce AVC denial. I tried to make changes mentioned by Daniel. Could you test it if there is some progress? The scratch build is available in koji: http://koji.fedoraproject.org/koji/taskinfo?taskID=1796872 Thanks, regards Jiri
This bug appears to have been reported against 'rawhide' during the Fedora 12 development cycle. Changing version to '12'. More information and reason for this action is here: http://fedoraproject.org/wiki/BugZappers/HouseKeeping
*** This bug has been marked as a duplicate of bug 531374 ***