Bug 703163 - SELINUX_ERR message not captured when readahead-collector is running instead of auditd
Summary: SELINUX_ERR message not captured when readahead-collector is running instead ...
Keywords:
Status: CLOSED CANTFIX
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: readahead
Version: 6.1
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: rc
: ---
Assignee: Harald Hoyer
QA Contact: qe-baseos-daemons
URL:
Whiteboard:
Depends On:
Blocks: 545868
TreeView+ depends on / blocked
 
Reported: 2011-05-09 14:09 UTC by Jan Hutař
Modified: 2012-07-04 12:20 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-07-04 12:20:23 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Jan Hutař 2011-05-09 14:09:55 UTC
Description of problem:
I'm running script which causes SELINUX_ERR failure, but it is not reported in ~50% of cases.

After some debugging, when I have added `sleep 3m` to the beginning of the script, I have found out, that when the script is started, there is:

 * running "readahead-collector"
 * not running "auditd"

and 3 minutes later:

 * not running "readahead-collector"
 * running "auditd"

When script is started after these 3 minutes, SELINUX_ERR nicely appears in /var/log/audit/audit.log.

I have discussed it with Miroslav Trmac, and he said, that in the boot-time, readahead-collector replaces auditd and that readahead-collector might just drop messages he is not interested in.

If this is exact, should readahead-collector be fixed, or should I keep mentioned workaround in my script (as I want that SELINUX_ERR to be reported)?

Comment 2 RHEL Program Management 2011-05-09 14:28:15 UTC
This request was evaluated by Red Hat Product Management for
inclusion in the current release of Red Hat Enterprise Linux.
Because the affected component is not scheduled to be updated
in the current release, Red Hat is unfortunately unable to
address this request at this time. Red Hat invites you to
ask your support representative to propose this request, if
appropriate and relevant, in the next release of Red Hat
Enterprise Linux. If you would like it considered as an
exception in the current release, please ask your support
representative.

Comment 3 Harald Hoyer 2012-07-04 12:20:23 UTC
(In reply to comment #0)
> Description of problem:
> I'm running script which causes SELINUX_ERR failure, but it is not reported
> in ~50% of cases.
> 
> After some debugging, when I have added `sleep 3m` to the beginning of the
> script, I have found out, that when the script is started, there is:
> 
>  * running "readahead-collector"
>  * not running "auditd"
> 
> and 3 minutes later:
> 
>  * not running "readahead-collector"
>  * running "auditd"
> 
> When script is started after these 3 minutes, SELINUX_ERR nicely appears in
> /var/log/audit/audit.log.
> 
> I have discussed it with Miroslav Trmac, and he said, that in the boot-time,
> readahead-collector replaces auditd and that readahead-collector might just
> drop messages he is not interested in.
> 
> If this is exact, should readahead-collector be fixed, or should I keep
> mentioned workaround in my script (as I want that SELINUX_ERR to be
> reported)?

You should just deinstall readahead.


Note You need to log in before you can comment on or make changes to this bug.