Bug 541560 - SELinux is preventing /sbin/ip access to a leaked /dev/mull file descriptor.
Summary: SELinux is preventing /sbin/ip access to a leaked /dev/mull file descriptor.
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 12
Hardware: i386
OS: Linux
low
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:22d767605d2...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-11-26 10:49 UTC by Alexandre Thieme Reis
Modified: 2009-12-23 16:36 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2009-12-23 16:36:55 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Alexandre Thieme Reis 2009-11-26 10:49:14 UTC
Sumário:

SELinux is preventing /sbin/ip access to a leaked /dev/mull file descriptor.

Descrição detalhada:

[SElinux está em modo permissivo. Esse acesso não foi negado.]

SELinux denied access requested by the ip command. It looks like this is either
a leaked descriptor or ip output was redirected to a file it is not allowed to
access. Leaks usually can be ignored since SELinux is just closing the leak and
reporting the error. The application does not use the descriptor, so it will run
properly. If this is a redirection, you will not get output in the /dev/mull.
You should generate a bugzilla on selinux-policy, and it will get routed to the
appropriate package. You can safely ignore this avc.

Permitindo acesso:

You can generate a local policy module to allow this access - see FAQ
(http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385)

Informações adicionais:

Contexto de origem            system_u:system_r:ifconfig_t:s0
Contexto de destino           system_u:object_r:device_t:s0
Objetos de destino            /dev/mull [ file ]
Origem                        ip
Caminho da origem             /sbin/ip
Porta                         <Desconhecido>
Máquina                      (removed)
Pacotes RPM de origem         iproute-2.6.29-4.fc12
Pacotes RPM de destino        
RPM da política              selinux-policy-3.6.32-46.fc12
Selinux habilitado            True
Tipo de política             targeted
Modo reforçado               Permissive
Nome do plugin                leaks
Nome da máquina              (removed)
Plataforma                    Linux (removed) 2.6.31.6-134.fc12.i686 #1
                              SMP Mon Nov 16 21:09:17 EST 2009 i686 i686
Contador de alertas           6
Visto pela primeira vez em    Qua 25 Nov 2009 09:35:37 BRST
Visto pela última vez em     Qua 25 Nov 2009 15:00:23 BRST
ID local                      3c828c52-c2f8-4b5d-ab9b-820b466be2a5
Números de linha             

Mensagens de auditoria não p 

node=(removed) type=AVC msg=audit(1259168423.769:69): avc:  denied  { write } for  pid=2627 comm="ip" path="/dev/mull" dev=tmpfs ino=21009 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:object_r:device_t:s0 tclass=file

node=(removed) type=AVC msg=audit(1259168423.769:69): avc:  denied  { read write } for  pid=2627 comm="ip" path="socket:[12152]" dev=sockfs ino=12152 scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:system_r:pppd_t:s0 tclass=packet_socket

node=(removed) type=SYSCALL msg=audit(1259168423.769:69): arch=40000003 syscall=11 success=yes exit=0 a0=9137460 a1=9135520 a2=9137590 a3=9135520 items=0 ppid=2621 pid=2627 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ip" exe="/sbin/ip" subj=system_u:system_r:ifconfig_t:s0 key=(null)



Hash String generated from  selinux-policy-3.6.32-46.fc12,leaks,ip,ifconfig_t,device_t,file,write
audit2allow suggests:

#============= ifconfig_t ==============
allow ifconfig_t device_t:file write;
allow ifconfig_t pppd_t:packet_socket { read write };

Comment 1 Daniel Walsh 2009-11-30 15:33:06 UTC
What the heck is /dev/mull?  Did you somehow create a device called /dev/mull instead of /dev/null?

Both of these can be ignored.  I believe a bug has been filed on ppp leaking an open filedescriptor to the packet_socket.

Comment 2 Daniel Walsh 2009-12-01 20:23:19 UTC

*** This bug has been marked as a duplicate of bug 541107 ***


Note You need to log in before you can comment on or make changes to this bug.