Fedora Account System
Red Hat Associate
Red Hat Customer
Résumé: SELinux is preventing /sbin/consoletype access to a leaked packet_socket file descriptor. Description détaillée: [consoletype a un type permissif (consoletype_t). Cet accès n'a pas été refusé.] SELinux denied access requested by the consoletype command. It looks like this is either a leaked descriptor or consoletype output was redirected to a file it is not allowed to access. Leaks usually can be ignored since SELinux is just closing the leak and reporting the error. The application does not use the descriptor, so it will run properly. If this is a redirection, you will not get output in the packet_socket. You should generate a bugzilla on selinux-policy, and it will get routed to the appropriate package. You can safely ignore this avc. Autoriser l'accès: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Informations complémentaires: Contexte source system_u:system_r:consoletype_t:s0 Contexte cible system_u:system_r:pppd_t:s0 Objets du contexte packet_socket [ packet_socket ] source consoletype Chemin de la source /sbin/consoletype Port <Inconnu> Hôte (removed) Paquetages RPM source initscripts-9.02-1 Paquetages RPM cible Politique RPM selinux-policy-3.6.32-49.fc12 Selinux activé True Type de politique targeted Mode strict Enforcing Nom du plugin leaks Nom de l'hôte (removed) Plateforme Linux (removed) 2.6.31.6-145.fc12.i686 #1 SMP Sat Nov 21 16:28:23 EST 2009 i686 i686 Compteur d'alertes 8 Première alerte mar. 01 déc. 2009 06:56:09 CET Dernière alerte mer. 02 déc. 2009 10:26:08 CET ID local 368043ea-18db-47bf-8035-3a3c24d5bc7b Numéros des lignes Messages d'audit bruts node=(removed) type=AVC msg=audit(1259745968.47:22010): avc: denied { read write } for pid=2035 comm="consoletype" path="socket:[19082]" dev=sockfs ino=19082 scontext=system_u:system_r:consoletype_t:s0 tcontext=system_u:system_r:pppd_t:s0 tclass=packet_socket node=(removed) type=SYSCALL msg=audit(1259745968.47:22010): arch=40000003 syscall=11 success=yes exit=0 a0=8712400 a1=8712460 a2=870af38 a3=8712460 items=0 ppid=2034 pid=2035 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="consoletype" exe="/sbin/consoletype" subj=system_u:system_r:consoletype_t:s0 key=(null) Hash String generated from selinux-policy-3.6.32-49.fc12,leaks,consoletype,consoletype_t,pppd_t,packet_socket,read,write audit2allow suggests: #============= consoletype_t ============== allow consoletype_t pppd_t:packet_socket { read write };
*** This bug has been marked as a duplicate of bug 541107 ***