Bug 636579 - avc on boot: denied { associate } comm="udevd" name="hugepages"
Summary: avc on boot: denied { associate } comm="udevd" name="hugepages"
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: 14
Hardware: x86_64
OS: Linux
low
medium
Target Milestone: ---
Assignee: Daniel Walsh
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2010-09-22 15:54 UTC by Jeff Raber
Modified: 2010-09-25 05:38 UTC (History)
0 users

Fixed In Version: selinux-policy-3.9.5-3.fc14
Doc Type: Bug Fix
Doc Text:
Clone Of:
: 636586 (view as bug list)
Environment:
Last Closed: 2010-09-25 05:38:38 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
/var/log/dmesg, showing 2 avcs during boot. This bug is for the first avc (46.60 KB, text/plain)
2010-09-22 15:54 UTC, Jeff Raber
no flags Details

Description Jeff Raber 2010-09-22 15:54:14 UTC
Created attachment 448971 [details]
/var/log/dmesg, showing 2 avcs during boot.  This bug is for the first avc

Description of problem:
avc during cold boot after udevd starts

type=1400 audit(1285151150.610:4): avc:  denied  { associate } for  pid=473 comm="udevd" name="hugepages" scontext=system_u:object_r:hugetlbfs_t:s0 tcontext=system_u:object_r:device_t:s0 tclass=filesystem

Version-Release number of selected component (if applicable):
selinux-policy-targeted-3.9.3-1.fc14.noarch
selinux-policy-3.9.3-1.fc14.noarch
udev-161-2.fc14.x86_64

How reproducible:
Seems like 100% (but I've only seen it 3 times)

Steps to Reproduce:
1. Cold boot laptop (doesn't seem to happen on a warm boot)
2. Notice the AVC when udev starts
  
Actual results:
AVC displayed in boot messages and logged in /dev/dmesg

Expected results:
No AVC.

Additional info:
This is a fresh F14 RC3 install from DVD, less than 12 hours old.  I have only installed 3 packages post-installation: pidgin, evolution-exchange & trousers.
Smolt profile: http://www.smolts.org/client/show/pub_0f5426ff-4588-4b7d-b80a-bca736d583bb

Comment 1 Daniel Walsh 2010-09-22 20:06:57 UTC
Fixed in selinux-policy-3.9.5-3.fc14

Comment 2 Fedora Update System 2010-09-22 23:03:32 UTC
selinux-policy-3.9.5-3.fc14 has been submitted as an update for Fedora 14.
https://admin.fedoraproject.org/updates/selinux-policy-3.9.5-3.fc14

Comment 3 Fedora Update System 2010-09-23 19:33:13 UTC
selinux-policy-3.9.5-3.fc14 has been pushed to the Fedora 14 testing repository.  If problems still persist, please make note of it in this bug report.
 If you want to test the update, you can install it with 
 su -c 'yum --enablerepo=updates-testing update selinux-policy'.  You can provide feedback for this update here: https://admin.fedoraproject.org/updates/selinux-policy-3.9.5-3.fc14

Comment 4 Fedora Update System 2010-09-25 05:37:40 UTC
selinux-policy-3.9.5-3.fc14 has been pushed to the Fedora 14 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.