Hide Forgot
Description of problem: Version-Release number of selected component (if applicable): selinux-policy-targeted-3.7.19-145.el6.noarch selinux-policy-doc-3.7.19-145.el6.noarch selinux-policy-mls-3.7.19-145.el6.noarch selinux-policy-3.7.19-145.el6.noarch selinux-policy-minimum-3.7.19-145.el6.noarch sblim-sfcb-1.3.11-2.el6.x86_64 How reproducible: always Steps to Reproduce: # service sblim-sfcb status sfcb is not running # run_init service sblim-sfcb start Authenticating root. Password: [ OK ] # service sblim-sfcb status sfcb (15147 15135 15132 15130 15128 15127 15124 15123) is running # ps -efZ | grep initrc_t system_u:system_r:initrc_t:s0 root 15123 1 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15124 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15127 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15128 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15130 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15132 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15135 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d system_u:system_r:initrc_t:s0 root 15147 15123 0 21:19 ? 00:00:00 /usr/sbin/sfcbd -d unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 root 15181 12100 0 21:19 pts/1 00:00:00 grep initrc_t # Actual results: * sfcbd runs as initrc_t Expected results: * sfcbd runs in its own SELinux domain
The daemon is not confined by SELinux. Please help SELinux folks to create a suitable policy module. You know that we should minimize the number of programs running as initrc_t, don't you?
This request was evaluated by Red Hat Product Management for inclusion in the current release of Red Hat Enterprise Linux. Because the affected component is not scheduled to be updated in the current release, Red Hat is unable to address this request at this time. Red Hat invites you to ask your support representative to propose this request, if appropriate, in the next release of Red Hat Enterprise Linux.
sent patch.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHBA-2014-1568.html