Bug 619882 - SELinux is preventing vsftpd (ftpd_t) "dac_override" to <Unknown> (ftpd_t).
Summary: SELinux is preventing vsftpd (ftpd_t) "dac_override" to <Unknown> (ftpd...
Status: CLOSED DUPLICATE of bug 538428
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy   
(Show other bugs)
Version: 13
Hardware: x86_64
OS: Linux
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Fedora Extras Quality Assurance
Whiteboard: setroubleshoot_trace_hash:cb3c867c2c8...
Depends On:
TreeView+ depends on / blocked
Reported: 2010-07-30 18:56 UTC by Răzvan Sandu
Modified: 2010-08-02 11:52 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2010-08-02 11:52:49 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

Description Răzvan Sandu 2010-07-30 18:56:16 UTC

SELinux is preventing vsftpd (ftpd_t) "dac_override" to <Unknown> (ftpd_t).

Detailed Description:

[SELinux is in permissive mode. This access was not denied.]

SELinux denied access requested by vsftpd. The current boolean settings do not
allow this access. If you have not setup vsftpd to require this access this may
signal an intrusion attempt. If you do intend this access you need to change the
booleans on this system to allow the access.

Allowing Access:

One of the following booleans is set incorrectly: allow_ftpd_full_access,

Fix Command:

Choose one of the following to allow access:
Allow ftp servers to login to local users and read/write all files on the
system, governed by DAC.
# setsebool -P allow_ftpd_full_access 1
Allow ftp to read and write files in the user home directories
# setsebool -P ftp_home_dir 1

Additional Information:

Source Context                unconfined_u:system_r:ftpd_t:s0-s0:c0.c1023
Target Context                unconfined_u:system_r:ftpd_t:s0-s0:c0.c1023
Target Objects                None [ capability ]
Source                        vsftpd
Source Path                   /usr/sbin/vsftpd
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           vsftpd-2.1.2-2.fc11
Target RPM Packages           
Policy RPM                    selinux-policy-3.6.12-98.fc11
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Permissive
Plugin Name                   catchall_boolean
Host Name                     (removed)
Platform                      Linux (removed)
                     #1 SMP Thu Feb 11
                              07:06:34 UTC 2010 x86_64 x86_64
Alert Count                   3
First Seen                    Mi 19 mai 2010 00:05:50 +0000
Last Seen                     Mi 19 mai 2010 00:13:53 +0000
Local ID                      5ac72285-bad3-4eaf-8ba4-57c38c2b8118
Line Numbers                  

Raw Audit Messages            

node=(removed) type=AVC msg=audit(1274217233.370:32116): avc:  denied  { dac_override } for  pid=16712 comm="vsftpd" capability=1 scontext=unconfined_u:system_r:ftpd_t:s0-s0:c0.c1023 tcontext=unconfined_u:system_r:ftpd_t:s0-s0:c0.c1023 tclass=capability

node=(removed) type=SYSCALL msg=audit(1274217233.370:32116): arch=c000003e syscall=4 success=no exit=-2 a0=7f21436bbb10 a1=7fffdfdd72d0 a2=7fffdfdd72d0 a3=20 items=0 ppid=0 pid=16712 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm="vsftpd" exe="/usr/sbin/vsftpd" subj=unconfined_u:system_r:ftpd_t:s0-s0:c0.c1023 key=(null)

Hash String generated from  catchall_boolean,vsftpd,ftpd_t,ftpd_t,capability,dac_override
audit2allow suggests:

#============= ftpd_t ==============
#!!!! This avc can be allowed using one of the these booleans:
#     allow_ftpd_full_access, ftp_home_dir

allow ftpd_t self:capability dac_override;

Comment 1 Miroslav Grepl 2010-08-02 11:52:49 UTC

*** This bug has been marked as a duplicate of bug 538428 ***

Note You need to log in before you can comment on or make changes to this bug.