Hide Forgot
Description of problem: This message is reported every login or restarting NetworkManager.service. Version-Release number of selected component (if applicable): NetworkManager-0.9.3.995-0.6.git20120314.fc17.x86_64 evolution-NetworkManager-3.3.91-1.fc17.x86_64 libselinux-devel-2.1.9-9.fc17.x86_64 libselinux-python-2.1.9-9.fc17.x86_64 selinux-policy-3.10.0-95.fc17.noarch NetworkManager-openvpn-0.9.3.995-1.git20120302.fc17.x86_64 NetworkManager-glib-0.9.3.995-0.6.git20120314.fc17.x86_64 selinux-policy-doc-3.10.0-95.fc17.noarch NetworkManager-gnome-0.9.3.995-0.6.git20120314.fc17.x86_64 NetworkManager-openconnect-0.9.3.995-1.git20120302.fc17.x86_64 libselinux-utils-2.1.9-9.fc17.x86_64 NetworkManager-pptp-0.9.3.995-1.git20120302.fc17.x86_64 selinux-policy-targeted-3.10.0-95.fc17.noarch libselinux-2.1.9-9.fc17.x86_64 NetworkManager-gtk-0.9.3.995-0.6.git20120314.fc17.x86_64 NetworkManager-vpnc-0.9.3.995-1.git20120302.fc17.x86_64 Steps to Reproduce: 1. Login or 2. systemctl restart NetworkManager.service Actual results: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. ***** Plugin catchall (100. confidence) suggests *************************** If you believe that NetworkManager should be allowed read access on the sysctl.conf file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep NetworkManager /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:NetworkManager_t:s0 Target Context system_u:object_r:system_conf_t:s0 Target Objects /etc/sysctl.conf [ file ] Source NetworkManager Source Path NetworkManager Port <Unknown> Host local Source RPM Packages NetworkManager-0.9.3.995-0.6.git20120314.fc17.x86_ 64 Target RPM Packages initscripts-9.36-1.fc17.x86_64 Policy RPM selinux-policy-3.10.0-95.fc17.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name local Platform Linux local 3.3.0-0.rc7.git0.2.fc17.x86_64 #1 SMP Mon Mar 12 16:56:58 UTC 2012 x86_64 x86_64 Alert Count 4 First Seen Mon 19 Mar 2012 05:51:54 PM CET Last Seen Mon 19 Mar 2012 06:03:51 PM CET Local ID ce278820-5781-4562-9606-69235fb7ce60 Raw Audit Messages type=AVC msg=audit(1332176631.350:340): avc: denied { read } for pid=1892 comm="NetworkManager" name="sysctl.conf" dev="sda8" ino=162063 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:system_conf_t:s0 tclass=file type=SYSCALL msg=audit(1332176631.350:340): arch=x86_64 syscall=open success=no exit=EACCES a0=4c7322 a1=0 a2=666e6f a3=11 items=0 ppid=1 pid=1892 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=NetworkManager exe=/usr/sbin/NetworkManager subj=system_u:system_r:NetworkManager_t:s0 key=(null) Hash: NetworkManager,NetworkManager_t,system_conf_t,file,read audit2allowunable to open /sys/fs/selinux/policy: Permission denied audit2allow -Runable to open /sys/fs/selinux/policy: Permission denied More info: cat /var/log/messages | grep sysctl Mar 18 14:18:56 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager (deleted) from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l c09be844-a227-427d-865f-57c10d596c3c Mar 18 15:51:37 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager (deleted) from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ade65fa6-a014-46ba-9579-2af9c4932615 Mar 18 17:21:28 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager (deleted) from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ca68b2a8-f9a9-4e78-9b37-1f543a4c6f4a Mar 18 17:38:50 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l 88b0545d-34c8-4645-96f6-2a17b951a19c Mar 18 21:13:33 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l b9f72368-d2bb-4513-a127-0c5140d7d308 Mar 19 10:31:28 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l 9d3f9a6e-9aa8-4b58-921a-ee0955c7bb96 Mar 19 14:52:29 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l 9d3f9a6e-9aa8-4b58-921a-ee0955c7bb96 Mar 19 15:15:29 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l 1d1dd229-4f92-498f-9a4a-74ecf7f1291c Mar 19 15:18:01 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l 00e47e54-9926-40e6-a81b-c22a66de0dd1 Mar 19 17:33:28 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l a4440a05-3f95-433b-90ac-629d06639b84 Mar 19 17:33:28 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l a4440a05-3f95-433b-90ac-629d06639b84 Mar 19 17:33:28 local setroubleshoot: SELinux is preventing /usr/sbin/NetworkManager from getattr access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ee897b08-2e9d-43bf-bc84-1e6fedd1f8dc Mar 19 17:52:03 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ce278820-5781-4562-9606-69235fb7ce60 Mar 19 18:02:20 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ce278820-5781-4562-9606-69235fb7ce60 Mar 19 18:03:11 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ce278820-5781-4562-9606-69235fb7ce60 Mar 19 18:03:51 local setroubleshoot: SELinux is preventing NetworkManager from read access on the file /etc/sysctl.conf. For complete SELinux messages. run sealert -l ce278820-5781-4562-9606-69235fb7ce60 [root@local ~]#
The AVC message disappears with selinux-policy-3.10.0-104.fc17 .
Closing based on comment #1.