Hide Forgot
SELinux is preventing /sbin/chkconfig from 'getattr' accesses on the file /etc/rc.d/init.d/avahi-daemon. ***** Plugin catchall (100. confidence) suggests *************************** If you believe that chkconfig should be allowed getattr access on the avahi-daemon file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep chkconfig /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:gnomeclock_t:s0-s0:c0.c1023 Target Context system_u:object_r:avahi_initrc_exec_t:s0 Target Objects /etc/rc.d/init.d/avahi-daemon [ file ] Source chkconfig Source Path /sbin/chkconfig Port <Unknown> Host (removed) Source RPM Packages chkconfig-1.3.49-1.fc15 Target RPM Packages avahi-0.6.28-7.fc15 Policy RPM selinux-policy-3.9.13-9.fc15 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 2.6.38-0.rc4.git0.1.fc15.x86_64 #1 SMP Tue Feb 8 01:57:21 UTC 2011 x86_64 x86_64 Alert Count 1 First Seen Wed 09 Feb 2011 04:29:17 PM CST Last Seen Wed 09 Feb 2011 04:29:17 PM CST Local ID e1e27d77-4bd2-4a91-a902-684581c31fb6 Raw Audit Messages type=AVC msg=audit(1297290557.627:162): avc: denied { getattr } for pid=7721 comm="chkconfig" path="/etc/rc.d/init.d/avahi-daemon" dev=dm-1 ino=525030 scontext=system_u:system_r:gnomeclock_t:s0-s0:c0.c1023 tcontext=system_u:object_r:avahi_initrc_exec_t:s0 tclass=file type=SYSCALL msg=audit(1297290557.627:162): arch=x86_64 syscall=stat success=no exit=EACCES a0=7fff6ecc7b50 a1=7fff6ecc7ac0 a2=7fff6ecc7ac0 a3=0 items=0 ppid=7680 pid=7721 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=chkconfig exe=/sbin/chkconfig subj=system_u:system_r:gnomeclock_t:s0-s0:c0.c1023 key=(null) Hash: chkconfig,gnomeclock_t,avahi_initrc_exec_t,file,getattr audit2allow #============= gnomeclock_t ============== allow gnomeclock_t avahi_initrc_exec_t:file getattr; audit2allow -R #============= gnomeclock_t ============== allow gnomeclock_t avahi_initrc_exec_t:file getattr;
Fixed in the latest rawhide policy. selinux-policy-3.9.14-2.fc15
*** Bug 676499 has been marked as a duplicate of this bug. ***
*** Bug 676500 has been marked as a duplicate of this bug. ***
*** Bug 676501 has been marked as a duplicate of this bug. ***
*** Bug 676503 has been marked as a duplicate of this bug. ***
*** Bug 676504 has been marked as a duplicate of this bug. ***
*** Bug 676505 has been marked as a duplicate of this bug. ***
*** Bug 676506 has been marked as a duplicate of this bug. ***
*** Bug 676507 has been marked as a duplicate of this bug. ***
*** Bug 676508 has been marked as a duplicate of this bug. ***
*** Bug 676509 has been marked as a duplicate of this bug. ***
*** Bug 676510 has been marked as a duplicate of this bug. ***
*** Bug 676511 has been marked as a duplicate of this bug. ***
*** Bug 676512 has been marked as a duplicate of this bug. ***
*** Bug 676513 has been marked as a duplicate of this bug. ***
Miroslav this should probably be dontaudit. init_dontaudit_getattr_all_script_files(gnomeclock_t)
John if you get lots of AVC's that look the same, please report it once and comment in the report that you got lots of other similar ones. Otherwise you waste yours and our time closing duplicates.