Fedora Account System
Red Hat Associate
Red Hat Customer
This is from a fresh Fedora 13 install. It happens as soon as you start up libvirtd, and I suggest that it should be an F13 blocker because it's such an obvious bug. Description of problem: SELinux is preventing /sbin/ip6tables-multi access to a leaked /proc/mtrr file descriptor. Detailed Description: [iptables has a permissive type (iptables_t). This access was not denied.] SELinux denied access requested by the ip6tables command. It looks like this is either a leaked descriptor or ip6tables output was redirected to a file it is not allowed to access. Leaks usually can be ignored since SELinux is just closing the leak and reporting the error. The application does not use the descriptor, so it will run properly. If this is a redirection, you will not get output in the /proc/mtrr. You should generate a bugzilla on selinux-policy, and it will get routed to the appropriate package. You can safely ignore this avc. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Additional Information: Source Context unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 Target Context system_u:object_r:mtrr_device_t:s0 Target Objects /proc/mtrr [ file ] Source iptables Source Path /sbin/iptables-multi Port <Unknown> Host thinkpad.home.annexia.org Source RPM Packages iptables-ipv6-1.4.6-2.fc13 Target RPM Packages Policy RPM selinux-policy-3.7.11-1.fc13 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name leaks Host Name thinkpad.home.annexia.org Platform Linux thinkpad.home.annexia.org 2.6.33-1.fc13.i686.PAE #1 SMP Wed Feb 24 19:54:49 UTC 2010 i686 i686 Alert Count 299 First Seen Mon 08 Mar 2010 07:52:35 PM GMT Last Seen Mon 08 Mar 2010 07:52:35 PM GMT Local ID d189845d-4780-440f-9689-2ff43738bdb8 Line Numbers Raw Audit Messages node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=AVC msg=audit(1268077955.535:92): avc: denied { write } for pid=4463 comm="ip6tables" path="/proc/mtrr" dev=proc ino=4026531909 scontext=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mtrr_device_t:s0 tclass=file node=thinkpad.home.annexia.org type=SYSCALL msg=audit(1268077955.535:92): arch=40000003 syscall=11 success=yes exit=0 a0=8434810 a1=8412c40 a2=840f7b0 a3=8412c40 items=0 ppid=4453 pid=4463 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4 comm="ip6tables" exe="/sbin/ip6tables-multi" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) Version-Release number of selected component (if applicable): libvirt-0.7.6-1.fc13.i686 selinux-policy-3.7.11-1.fc13.noarch
(same comment I just posted in Bug 537427) netcf does run (via system(3)) "/etc/init.d/iptables condrestart", which looks like it could call ip6tables-multi (it calls "ip6tables" which, on F12 anyway, is a symlink to ip6tables-multi). netcf's system() call should be replaced with something like virRun from libvirt so that all the fds will be closed, but of course ip6tables-multi should also not be writing to a fd it didn't open itself. I'll try to replace system() in netcf this week.
I've posted two fixes to the netcf-devel mailing list: https://fedorahosted.org/pipermail/netcf-devel/2010-March/000407.html https://fedorahosted.org/pipermail/netcf-devel/2010-March/000408.html
Discussed at last week's and today's blocker meetings. We agreed this is a blocker. Can we hope the patches will be approved and applied soon? Thanks! -- Fedora Bugzappers volunteer triage team https://fedoraproject.org/wiki/BugZappers
netcf-0.1.6-1.fc12 has been submitted as an update for Fedora 12. http://admin.fedoraproject.org/updates/netcf-0.1.6-1.fc12
netcf-0.1.6-1.fc13 has been submitted as an update for Fedora 13. http://admin.fedoraproject.org/updates/netcf-0.1.6-1.fc13
netcf-0.1.6-1.fc11 has been submitted as an update for Fedora 11. http://admin.fedoraproject.org/updates/netcf-0.1.6-1.fc11
netcf-0.1.6-1.fc13 has been pushed to the Fedora 13 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update netcf'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/netcf-0.1.6-1.fc13
netcf-0.1.6-1.fc12 has been pushed to the Fedora 12 testing repository. If problems still persist, please make note of it in this bug report. If you want to test the update, you can install it with su -c 'yum --enablerepo=updates-testing update netcf'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/netcf-0.1.6-1.fc12
This update now has +3 karma; can it pleased be pushed to f13 stable so we can close off this release blocker report? Thanks. -- Fedora Bugzappers volunteer triage team https://fedoraproject.org/wiki/BugZappers
netcf-0.1.6-1.fc13 has been pushed to the Fedora 13 stable repository. If problems still persist, please make note of it in this bug report.
netcf-0.1.6-1.fc11 has been pushed to the Fedora 11 stable repository. If problems still persist, please make note of it in this bug report.
netcf-0.1.6-1.fc12 has been pushed to the Fedora 12 stable repository. If problems still persist, please make note of it in this bug report.
*** Bug 584158 has been marked as a duplicate of this bug. ***
*** Bug 584160 has been marked as a duplicate of this bug. ***