Hide Forgot
Description of problem: Version-Release number of selected component (if applicable): selinux-policy-targeted-3.7.19-145.el6.noarch selinux-policy-doc-3.7.19-145.el6.noarch selinux-policy-mls-3.7.19-145.el6.noarch selinux-policy-3.7.19-145.el6.noarch selinux-policy-minimum-3.7.19-145.el6.noarch isns-utils-0.93-1.0.el6.x86_64 How reproducible: always Steps to Reproduce: # service isnsd status isnsd is stopped # run_init service isnsd start Authenticating root. Password: Starting iSNS Server: [ OK ] # service isnsd status isnsd (pid 14560) is running... # ps -efZ | grep initrc_t system_u:system_r:initrc_t:s0 root 14560 1 0 20:59 ? 00:00:00 isnsd unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 root 14571 12100 0 20:59 pts/1 00:00:00 grep initrc_t # Actual results: * isnsd runs as initrc_t Expected results: * isnsd runs in its own SELinux domain
The daemon is not confined by SELinux. Please help SELinux folks to create a suitable policy module. You know that we should minimize the number of programs running as initrc_t, don't you?
This request was not resolved in time for the current release. Red Hat invites you to ask your support representative to propose this request, if still desired, for consideration in the next release of Red Hat Enterprise Linux.
This request was erroneously removed from consideration in Red Hat Enterprise Linux 6.4, which is currently under development. This request will be evaluated for inclusion in Red Hat Enterprise Linux 6.4.
This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate, in the next release of Red Hat Enterprise Linux.
Patch send to Miroslav.
commit ea9b2b5e79461a7f27a00c15d742a14d77c297c0 Author: Lukas Vrabec <lvrabec> Date: Tue Apr 22 19:29:35 2014 +0200 Added support for isns
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2014-1568.html