Hide Forgot
While working on the ctdb selinux policy Miroslav pointed out that ctdbd leaks a file descriptor which leads to selinux AVCs. +++ This bug was initially created as a clone of Bug #672641 +++ --- Additional comment from mgrepl on 2011-07-28 08:14:07 EDT --- Also we see #============= ifconfig_t ============== allow ifconfig_t anon_inodefs_t:file { read write }; #============= iptables_t ============== allow iptables_t anon_inodefs_t:file write; which looks like ctdb is leaking an open file descriptor to anon_inodefs.
Verified with ctdb-1.0.114.3-3.el6.x86_64, the AVC does not show up when starting ctdb.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2011-1574.html