Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: SELinux is preventing consoletype (consoletype_t) "read write" pppd_t. Detailed Description: [consoletype has a permissive type (consoletype_t). This access was not denied.] SELinux denied access requested by consoletype. It is not expected that this access is required by consoletype and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi) against this package. Additional Information: Source Context system_u:system_r:consoletype_t:s0 Target Context system_u:system_r:pppd_t:s0 Target Objects socket [ packet_socket ] Source consoletype Source Path /sbin/consoletype Port <Unknown> Host (removed) Source RPM Packages initscripts-8.95-1 Target RPM Packages Policy RPM selinux-policy-3.6.12-85.fc11 Selinux Enabled True Policy Type targeted MLS Enabled True Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.30.8-64.fc11.i586 #1 SMP Fri Sep 25 04:30:19 EDT 2009 i686 i686 Alert Count 2 First Seen Thu 22 Oct 2009 10:23:10 PM MSD Last Seen Thu 22 Oct 2009 11:23:19 PM MSD Local ID a5f00364-3893-47a2-9a00-00343c3821e8 Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1256239399.251:11): avc: denied { read write } for pid=1910 comm="consoletype" path="socket:[12568]" dev=sockfs ino=12568 scontext=system_u:system_r:consoletype_t:s0 tcontext=system_u:system_r:pppd_t:s0 tclass=packet_socket node=(removed) type=SYSCALL msg=audit(1256239399.251:11): arch=40000003 syscall=11 success=yes exit=0 a0=87173b8 a1=8716ed8 a2=8717080 a3=8716ed8 items=0 ppid=1909 pid=1910 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="consoletype" exe="/sbin/consoletype" subj=system_u:system_r:consoletype_t:s0 key=(null) Hash String generated from selinux-policy-3.6.12-85.fc11,catchall,consoletype,consoletype_t,pppd_t,packet_socket,read,write audit2allow suggests: #============= consoletype_t ============== allow consoletype_t pppd_t:packet_socket { read write };
pppd is leaking the file descriptor to the packet_socket. It should close this using fcntl on exec. Egor, you can ignore this, as It should not effect your functionality. You can add a rule using audit2allow if you want the message to stop. # grep avc /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp
Hi, I can't reproduce AVC denial. I tried to make changes mentioned by Daniel. Could you test it if there is some progress? The scratch build is available in koji: http://koji.fedoraproject.org/koji/taskinfo?taskID=1796872 Thanks, regards Jiri
This bug appears to have been reported against 'rawhide' during the Fedora 12 development cycle. Changing version to '12'. More information and reason for this action is here: http://fedoraproject.org/wiki/BugZappers/HouseKeeping
*** Bug 538154 has been marked as a duplicate of this bug. ***
*** Bug 524174 has been marked as a duplicate of this bug. ***
I have other sealerts in audit.log, what's the commands only for consoletype?
Not sure what you mean by the question.
May I use grep avc /var/log/audit/audit.log | grep consoletype | audit2allow -M mypol instead of the first command?
yes
*** This bug has been marked as a duplicate of bug 541107 ***