Bug 542654 - ntop triggers several AVC denials when starting
Summary: ntop triggers several AVC denials when starting
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 12
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2009-11-30 13:26 UTC by Göran Uddeborg
Modified: 2010-08-20 01:43 UTC (History)
2 users (show)

Fixed In Version: selinux-policy-3.6.32-120.fc12
Clone Of:
Environment:
Last Closed: 2010-01-04 21:45:11 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
AVC denials reported by ntop on startup. (27.35 KB, text/plain)
2009-11-30 13:26 UTC, Göran Uddeborg
no flags Details
AVC denials reported by ntop when connecting a browser to it (26.14 KB, text/plain)
2009-11-30 13:27 UTC, Göran Uddeborg
no flags Details
Denials after installing selinux-policy-targeted-3.6.32-52.fc12 (58.73 KB, text/plain)
2009-12-04 20:07 UTC, Göran Uddeborg
no flags Details
Denials after installing selinux-policy-targeted-3.6.32-55.fc12 (39.23 KB, application/octet-stream)
2009-12-10 11:15 UTC, Göran Uddeborg
no flags Details
Denials after installing selinux-policy-targeted-3.6.32-59.fc12 (38.06 KB, text/plain)
2009-12-20 16:11 UTC, Göran Uddeborg
no flags Details

Description Göran Uddeborg 2009-11-30 13:26:50 UTC
Created attachment 374747 [details]
AVC denials reported by ntop on startup.

Description of problem:
When running ntop in Fedora 12, a several AVC denials are reported.  This is with standard configurations, so I believe these should be allowed.

Version-Release number of selected component (if applicable):


How reproducible:
ntop-3.3.10-2.fc12.x86_64
selinux-policy-3.6.32-41.fc12.noarch
selinux-policy-targeted-3.6.32-41.fc12.noarch


Steps to Reproduce:
1. Install and enable ntop
  
Actual results:
Several AVC denials happen.

Expected results:
No denials.

Additional info:
Ntop seems to work as expected anyway, presumably because ntop_t is a permissive domain currently.

Comment 1 Göran Uddeborg 2009-11-30 13:27:42 UTC
Created attachment 374748 [details]
AVC denials reported by ntop when connecting a browser to it

Comment 2 Daniel Walsh 2009-11-30 14:48:38 UTC
Fixed in selinux-policy-3.6.32-52.fc12.noarch

Comment 3 Fedora Update System 2009-12-01 16:54:27 UTC
selinux-policy-3.6.32-52.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-52.fc12

Comment 4 Fedora Update System 2009-12-03 05:01:54 UTC
selinux-policy-3.6.32-52.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F12/FEDORA-2009-12549

Comment 5 Fedora Update System 2009-12-03 20:26:29 UTC
selinux-policy-3.6.32-55.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-55.fc12

Comment 6 Göran Uddeborg 2009-12-04 20:07:33 UTC
Created attachment 376181 [details]
Denials after installing selinux-policy-targeted-3.6.32-52.fc12

It seems the new policy launched a new set of AVC:s.  I attach the output of "ausearch -m avc -ts 20:45" after having upgraded selinux-policy-targeted to 3.6.32-52.fc12 from updates testing, and then restarted ntop, followed by a connection to it (http://localhost:3000/) from my browser.

Comment 7 Göran Uddeborg 2009-12-04 21:57:36 UTC
I just realized there is an denial to search nfs_t in my latest attachment.  That comes because I mount /usr/local via nfs on this host.  That is nothing the standard policy should support I guess.  Please disregard that particular one, and sorry for not cleaning up enough before submitting.

Comment 8 Fedora Update System 2009-12-04 23:44:34 UTC
selinux-policy-3.6.32-55.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F12/FEDORA-2009-12650

Comment 9 Fedora Update System 2009-12-08 07:51:15 UTC
selinux-policy-3.6.32-55.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 10 Göran Uddeborg 2009-12-10 11:15:03 UTC
Created attachment 377432 [details]
Denials after installing selinux-policy-targeted-3.6.32-55.fc12

Comment 11 Göran Uddeborg 2009-12-10 11:17:40 UTC
The problem does persist.

I attached the avc:s after upgrade to -52 previously.  Now I've upgraded to -55, and I still get all these avc:s.  See the new attachment for an updated list.  The first part is from when I started ntopd, and the later from when I connected to it from a web browser.

Comment 12 Daniel Walsh 2009-12-10 16:05:57 UTC
This is strange I don't see how this even installed,  the fixes were in there but the policy module had a conflict.

Fixed in selinux-policy-3.6.32-58.fc12.noarch

Comment 13 Fedora Update System 2009-12-16 13:52:31 UTC
selinux-policy-3.6.32-59.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-59.fc12

Comment 14 Fedora Update System 2009-12-18 04:40:49 UTC
selinux-policy-3.6.32-59.fc12 has been pushed to the Fedora 12 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F12/FEDORA-2009-13384

Comment 15 Göran Uddeborg 2009-12-20 16:11:08 UTC
Created attachment 379488 [details]
Denials after installing selinux-policy-targeted-3.6.32-59.fc12

I upgraded to -59, but I still see the AVC:s when restarting ntop.  (At least most of them.  It looks like the same list, but I haven't looked close enough to see if a single one may have been removed or added.)

In this log, ntop is started at 12:36, and at 16:50 I connect my browser to it.

Did it go wrong this time too?  Or did I do something wrong?  There are some log entries in messages from the time when I upgraded, that I only partially understand:

Dec 20 12:35:26 freddi kernel: SELinux:  Context unconfined_u:unconfined_r:winbi
nd_helper_t:s0-s0:c0.c1023 became invalid (unmapped).
Dec 20 12:35:26 freddi dbus: avc:  received policyload notice (seqno=2) 
Dec 20 12:35:26 freddi dbus: Can't send to audit system: USER_AVC avc:  received
 policyload notice (seqno=2) : exe="?" sauid=81 hostname=? addr=? terminal=?
Dec 20 12:35:26 freddi dbus: Reloaded configuration
Dec 20 12:35:29 freddi kernel: SELinux:  Context system_u:object_r:unconfined_mo
zilla_home_t:s0 is not valid (left unmapped).
Dec 20 12:35:39 freddi yum: Updated: selinux-policy-targeted-3.6.32-59.fc12.noar
ch

Comment 16 Daniel Walsh 2009-12-21 16:16:45 UTC
Yes you are right, there was a screw up in the ntop policy.

Fixed in selinux-policy-3.6.32-61.fc12.noarch

Comment 17 Fedora Update System 2009-12-22 21:54:28 UTC
selinux-policy-3.6.32-63.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-63.fc12

Comment 18 Fedora Update System 2009-12-23 21:30:29 UTC
selinux-policy-3.6.32-59.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 19 Göran Uddeborg 2009-12-27 12:47:07 UTC
Third time lucky!  With selinux-policy-3.6.32-63.fc12 I can run ntop without triggering any new AVC:s. :-)

Comment 20 Daniel Walsh 2009-12-30 00:41:55 UTC
Please update karma.

Comment 21 Fedora Update System 2010-01-05 22:56:09 UTC
selinux-policy-3.6.32-63.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 22 Fedora Update System 2010-08-05 13:17:44 UTC
selinux-policy-3.6.32-120.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/selinux-policy-3.6.32-120.fc12

Comment 23 Fedora Update System 2010-08-20 01:38:08 UTC
selinux-policy-3.6.32-120.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.