Fedora Account System
Red Hat Associate
Red Hat Customer
libreport version: 2.0.10 executable: /usr/bin/python2.7 hashmarkername: setroubleshoot kernel: 3.4.2-4.fc17.x86_64 time: sab 16 giu 2012 09:42:32 CEST description: :SELinux is preventing /usr/sbin/rpc.statd from using the 'setpcap' capabilities. : :***** Plugin catchall (100. confidence) suggests *************************** : :If si pensa che rpc.statd dovrebbe avere funzionalità setpcap in modo predefinito. :Then si dovrebbe riportare il problema come bug. :E' possibile generare un modulo di politica locale per consentire questo accesso. :Do :consentire questo accesso per il momento eseguendo: :# grep rpc.statd /var/log/audit/audit.log | audit2allow -M mypol :# semodule -i mypol.pp : :Additional Information: :Source Context system_u:system_r:rpcd_t:s0 :Target Context system_u:system_r:rpcd_t:s0 :Target Objects [ capability ] :Source rpc.statd :Source Path /usr/sbin/rpc.statd :Port <Sconosciuto> :Host (removed) :Source RPM Packages nfs-utils-1.2.6-2.fc17.x86_64 :Target RPM Packages :Policy RPM selinux-policy-3.10.0-131.fc17.noarch :Selinux Enabled True :Policy Type targeted :Enforcing Mode Permissive :Host Name (removed) :Platform Linux (removed) 3.4.2-4.fc17.x86_64 #1 SMP Thu : Jun 14 22:22:05 UTC 2012 x86_64 x86_64 :Alert Count 1 :First Seen sab 16 giu 2012 09:42:04 CEST :Last Seen sab 16 giu 2012 09:42:04 CEST :Local ID ff21208c-33d8-4441-97e3-b4be068cce91 : :Raw Audit Messages :type=AVC msg=audit(1339832524.309:77): avc: denied { setpcap } for pid=1949 comm="rpc.statd" capability=8 scontext=system_u:system_r:rpcd_t:s0 tcontext=system_u:system_r:rpcd_t:s0 tclass=capability : : :type=SYSCALL msg=audit(1339832524.309:77): arch=x86_64 syscall=prctl success=yes exit=0 a0=18 a1=0 a2=0 a3=0 items=0 ppid=1948 pid=1949 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=rpc.statd exe=/usr/sbin/rpc.statd subj=system_u:system_r:rpcd_t:s0 key=(null) : :Hash: rpc.statd,rpcd_t,rpcd_t,capability,setpcap : :audit2allowunable to open /sys/fs/selinux/policy: Permission denied : : :audit2allow -Runable to open /sys/fs/selinux/policy: Permission denied : :
SELinux is preventing /usr/sbin/rpc.statd from using the 'setpcap' capabilities. ***** Plugin catchall (100. confidence) suggests *************************** If you believe that rpc.statd should have the setpcap capability by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep rpc.statd /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:rpcd_t:s0 Target Context system_u:system_r:rpcd_t:s0 Target Objects [ capability ] Source rpc.statd Source Path /usr/sbin/rpc.statd Port <Unknown> Host (removed) Source RPM Packages nfs-utils-1.2.6-2.fc17.x86_64 Target RPM Packages Policy RPM selinux-policy-3.10.0-130.fc17.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 3.4.2-4.fc17.x86_64 #1 SMP Thu Jun 14 22:22:05 UTC 2012 x86_64 x86_64 Alert Count 1 First Seen Mon 18 Jun 2012 08:37:16 AM PDT Last Seen Mon 18 Jun 2012 08:37:16 AM PDT Local ID cf9a09da-b470-4ab1-8592-455c73a3e05b Raw Audit Messages type=AVC msg=audit(1340033836.424:38): avc: denied { setpcap } for pid=1055 comm="rpc.statd" capability=8 scontext=system_u:system_r:rpcd_t:s0 tcontext=system_u:system_r:rpcd_t:s0 tclass=capability type=SYSCALL msg=audit(1340033836.424:38): arch=x86_64 syscall=prctl success=no exit=EPERM a0=18 a1=0 a2=0 a3=0 items=0 ppid=1041 pid=1055 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=rpc.statd exe=/usr/sbin/rpc.statd subj=system_u:system_r:rpcd_t:s0 key=(null) Hash: rpc.statd,rpcd_t,rpcd_t,capability,setpcap audit2allowunable to open /sys/fs/selinux/policy: Permission denied audit2allow -Runable to open /sys/fs/selinux/policy: Permission denied
Fixed in selinux-policy-3.10.0-131.fc17
selinux-policy-3.10.0-132.fc17 has been submitted as an update for Fedora 17. https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-132.fc17
selinux-policy-3.10.0-132.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.
I still get this with -132: time->Wed Jun 20 14:07:00 2012 type=SYSCALL msg=audit(1340222820.642:33): arch=40000003 syscall=172 success=no exit=-1 a0=18 a1=0 a2=0 a3=0 items=0 ppid=833 pid=834 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="rpc.statd" exe="/usr/sbin/rpc.statd" subj=system_u:system_r:rpcd_t:s0 key=(null) type=AVC msg=audit(1340222820.642:33): avc: denied { setpcap } for pid=834 comm="rpc.statd" capability=8 scontext=system_u:system_r:rpcd_t:s0 tcontext=system_u:system_r:rpcd_t:s0 tclass=capability Jun 20 14:07:00 orca rpc.statd[834]: Unable to prune capability 0 from bounding set: Operation not permitted Jun 20 14:07:00 orca systemd[1]: nfs-lock.service: control process exited, code=exited status=1 Jun 20 14:07:00 orca systemd[1]: Unit nfs-lock.service entered failed state.
Fixed in selinux-policy-3.10.0-133.fc17
selinux-policy-3.10.0-134.fc17 has been submitted as an update for Fedora 17. https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-134.fc17
Package selinux-policy-3.10.0-134.fc17: * should fix your issue, * was pushed to the Fedora 17 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing selinux-policy-3.10.0-134.fc17' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-10008/selinux-policy-3.10.0-134.fc17 then log in and leave karma (feedback).
selinux-policy-3.10.0-134.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.