Bug 680221 - tps srpmtest failure due to avc failure at config.log
Summary: tps srpmtest failure due to avc failure at config.log
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: NetworkManager
Version: 6.0
Hardware: All
OS: Linux
low
low
Target Milestone: rc
: ---
Assignee: Dan Williams
QA Contact: Desktop QE
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-02-24 17:30 UTC by Vladimir Benes
Modified: 2011-10-25 17:43 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-10-25 17:42:49 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Vladimir Benes 2011-02-24 17:30:24 UTC
Description of problem:

Running: /sbin/ausearch -sv no -m AVC -ts 02/17/2011 12:44:47 SELinux Check: 

FAIL SELinux AVC messages found: type=1400 audit(1297964727.372:32104): avc: 
denied { append } for pid=14594 comm="dhclient" path="/usr/src/redhat/BUILD/NetworkManager-0.8.1/config.log" dev=cciss/c0d0p2 ino=4164994 scontext=unconfined_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:usr_t:s0 tclass=file 

TPSHINT: It is possible that other stable systems activity has caused this issue. If you are sure that this is the case, you may waive this failure. If you have any doubts, RE-RUN tps to be sure. TPSRESULT: tps-srpmtest-selinux Returning: FAIL 

Version-Release number of selected component (if applicable):
NetworkManager-0.8.1-7.el6.src.rpm

Comment 1 Vladimir Benes 2011-02-24 17:34:36 UTC
it's looking like regression as there are no errors in z stream rhel6 package before:
http://nest.test.redhat.com/mnt/qa/scratch/i386-6s-m1/2010:10100/tps/tps.html

setting appropriate keywords

Comment 5 Dan Williams 2011-06-13 15:06:38 UTC
So the issue here is that the configure script needs to check the dhclient version to ensure it's >= 4.  That's only something that is done at build-time, not runtime.  No idea how we're supposed to handle build-time SELinux issues, since clearly a policy that allows this should not be applied to normal machines.

Comment 6 Dan Williams 2011-06-14 20:01:47 UTC
Dan; any idea what we do here for other packages?  Do we generally update SELinux policy just for issues rebuilding SRPMs?

Comment 7 Daniel Walsh 2011-06-14 20:52:05 UTC
I have no clue what is going on here.

This does not seem to be a runtime error.  I don't think we care about build errors.

Comment 9 Dan Williams 2011-10-25 15:50:16 UTC
So basically we either need to:

1) adjust selinux policy to allow certain operations at build time  but not at runtime (since this behavior isn't needed at runtime)

2) OR not use selinux on the build systems

Yes, we can patch out the dhclient version check for RHEL, but that's a hack since this shouldn't really be an issue in the first place, and this sort of thing happens in a few other places too.

Comment 10 Daniel Walsh 2011-10-25 17:42:49 UTC
So this only happens if you build NetworkManager as root, I am closing as not a bug.

Comment 11 Daniel Walsh 2011-10-25 17:43:40 UTC
We could change the build script to put a label on the log file.  I guess this build is happening from init?


Note You need to log in before you can comment on or make changes to this bug.