Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: SELinux is preventing dhclient-script (dhcpc_t) "read write" unconfined_t. Detailed Description: [dhclient-script has a permissive type (dhcpc_t). This access was not denied.] SELinux denied access requested by dhclient-script. It is not expected that this access is required by dhclient-script and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi) against this package. Additional Information: Source Context unconfined_u:system_r:dhcpc_t:s0 Target Context unconfined_u:unconfined_r:unconfined_t:s0 Target Objects socket [ unix_stream_socket ] Source dhclient-script Source Path /bin/bash Port <Unknown> Host (removed) Source RPM Packages bash-3.2-29.fc10 Target RPM Packages Policy RPM selinux-policy-3.5.13-18.fc10 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.27.5-117.fc10.i686 #1 SMP Tue Nov 18 12:19:59 EST 2008 i686 i686 Alert Count 2 First Seen Thu 26 Nov 2009 10:30:16 AM IST Last Seen Thu 26 Nov 2009 10:35:35 AM IST Local ID c3aacd45-c003-443a-85e8-ea4372e03a2c Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11759]" dev=sockfs ino=11759 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=AVC msg=audit(1259211935.401:110): avc: denied { read write } for pid=4346 comm="dhclient-script" path="socket:[11627]" dev=sockfs ino=11627 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=unix_stream_socket node=(removed) type=SYSCALL msg=audit(1259211935.401:110): arch=40000003 syscall=11 success=yes exit=0 a0=89d87e0 a1=8a02700 a2=89db6a0 a3=0 items=0 ppid=4293 pid=4346 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts1 ses=1 comm="dhclient-script" exe="/bin/bash" subj=unconfined_u:system_r:dhcpc_t:s0 key=(null) Hash String generated from selinux-policy-3.5.13-18.fc10,catchall,dhclient-script,dhcpc_t,unconfined_t,unix_stream_socket,read,write audit2allow suggests: audit2allow is not installed.
*** This bug has been marked as a duplicate of bug 538428 ***