Bug 585963
| Summary: | SELinux is preventing /usr/libexec/ipsec/addconn "write" access on /dev/pts/0. | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Mark Wielaard <mjw> |
| Component: | selinux-policy | Assignee: | Daniel Walsh <dwalsh> |
| Status: | CLOSED CURRENTRELEASE | QA Contact: | Milos Malik <mmalik> |
| Severity: | medium | Docs Contact: | |
| Priority: | high | ||
| Version: | 6.0 | CC: | avagarwa, dwagelaar, mmalik |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | setroubleshoot_trace_hash:e48142e31451ab856b8657a589b6968f936b9712cfcc196b5534898e1f8aca15 | ||
| Fixed In Version: | selinux-policy-3.7.19-6.fc13.noarch | Doc Type: | Bug Fix |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2010-11-11 14:56:28 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
Mark Wielaard
2010-04-26 14:30:12 UTC
Some other avcs: Summary: SELinux is preventing /bin/rm "write" access on etc. Detailed Description: [SELinux is in permissive mode. This access was not denied.] SELinux denied access requested by rm. It is not expected that this access is required by rm and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context unconfined_u:system_r:ipsec_mgmt_t:s0 Target Context system_u:object_r:etc_t:s0 Target Objects etc [ dir ] Source rm Source Path /bin/rm Port <Unknown> Host springer.wildebeest.org Source RPM Packages coreutils-8.4-6.el6 Target RPM Packages filesystem-2.4.30-2.1.el6 Policy RPM selinux-policy-3.7.19-3.el6 Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Plugin Name catchall Host Name springer.wildebeest.org Platform Linux springer.wildebeest.org 2.6.32-22.el6.x86_64 #1 SMP Tue Apr 20 12:10:42 EDT 2010 x86_64 x86_64 Alert Count 3 First Seen Mon 26 Apr 2010 05:05:27 PM CEST Last Seen Mon 26 Apr 2010 05:05:27 PM CEST Local ID 81579864-2036-4711-941b-31e848863e6a Line Numbers Raw Audit Messages node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:105): avc: denied { write } for pid=8607 comm="rm" name="etc" dev=dm-0 ino=524293 scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=dir node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:105): avc: denied { remove_name } for pid=8607 comm="rm" name="resolv.conf" dev=dm-0 ino=524306 scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=dir node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:105): avc: denied { unlink } for pid=8607 comm="rm" name="resolv.conf" dev=dm-0 ino=524306 scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=system_u:object_r:net_conf_t:s0 tclass=file node=springer.wildebeest.org type=SYSCALL msg=audit(1272294327.307:105): arch=c000003e syscall=263 success=yes exit=0 a0=ffffffffffffff9c a1=19340f0 a2=0 a3=7fff69d43790 items=0 ppid=8604 pid=8607 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm="rm" exe="/bin/rm" subj=unconfined_u:system_r:ipsec_mgmt_t:s0 key=(null) Summary: SELinux is preventing /bin/bash "add_name" access on resolv.conf. Detailed Description: [SELinux is in permissive mode. This access was not denied.] SELinux denied access requested by _updown.netkey. It is not expected that this access is required by _updown.netkey and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context unconfined_u:system_r:ipsec_mgmt_t:s0 Target Context system_u:object_r:etc_t:s0 Target Objects resolv.conf [ dir ] Source _updown.netkey Source Path /bin/bash Port <Unknown> Host springer.wildebeest.org Source RPM Packages bash-4.1.2-2.el6 Target RPM Packages Policy RPM selinux-policy-3.7.19-3.el6 Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Plugin Name catchall Host Name springer.wildebeest.org Platform Linux springer.wildebeest.org 2.6.32-22.el6.x86_64 #1 SMP Tue Apr 20 12:10:42 EDT 2010 x86_64 x86_64 Alert Count 3 First Seen Mon 26 Apr 2010 05:05:27 PM CEST Last Seen Mon 26 Apr 2010 05:05:27 PM CEST Local ID c13e4ef5-e9bf-44a6-9257-0827d9a0ca60 Line Numbers Raw Audit Messages node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:106): avc: denied { add_name } for pid=8604 comm="_updown.netkey" name="resolv.conf" scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=system_u:object_r:etc_t:s0 tclass=dir node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:106): avc: denied { create } for pid=8604 comm="_updown.netkey" name="resolv.conf" scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file node=springer.wildebeest.org type=AVC msg=audit(1272294327.307:106): avc: denied { write } for pid=8604 comm="_updown.netkey" name="resolv.conf" dev=dm-0 ino=524306 scontext=unconfined_u:system_r:ipsec_mgmt_t:s0 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file node=springer.wildebeest.org type=SYSCALL msg=audit(1272294327.307:106): arch=c000003e syscall=2 success=yes exit=4294967424 a0=1ee36b0 a1=241 a2=1b6 a3=fffffffffffffff0 items=0 ppid=8603 pid=8604 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm="_updown.netkey" exe="/bin/bash" subj=unconfined_u:system_r:ipsec_mgmt_t:s0 key=(null) Fixed in selinux-policy-3.7.19-6.fc13.noarch This request was evaluated by Red Hat Product Management for inclusion in a Red Hat Enterprise Linux major release. Product Management has requested further review of this request by Red Hat Engineering, for potential inclusion in a Red Hat Enterprise Linux Major release. This request is not yet committed for inclusion. Red Hat Enterprise Linux 6.0 is now available and should resolve the problem described in this bug report. This report is therefore being closed with a resolution of CURRENTRELEASE. You may reopen this bug report if the solution does not work for you. |