Bug 845033 - selinux policy for iucvtty
selinux policy for iucvtty
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
Unspecified Linux
medium Severity medium
: rc
: ---
Assigned To: Miroslav Grepl
Milos Malik
Depends On:
  Show dependency treegraph
Reported: 2012-08-01 10:44 EDT by David Juran
Modified: 2013-02-21 03:27 EST (History)
3 users (show)

See Also:
Fixed In Version: selinux-policy-3.7.19-188.el6
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2013-02-21 03:27:23 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)
Module that solves the problem (494 bytes, text/plain)
2012-08-01 10:46 EDT, David Juran
no flags Details

External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2013:0314 normal SHIPPED_LIVE selinux-policy bug fix and enhancement update 2013-02-20 15:35:01 EST

  None (edit)
Description David Juran 2012-08-01 10:44:29 EDT
Description of problem:
On zLinux (s390x) there is a way to communicate between two VM:s running
on the same hypervisor using iucvcon (on the connecting side) and
iucvtty (on the receiver). These utilities are part of our s390utils
package. However, if selinux is enabled (well enforcing of course), all
of this fails since iucvtty won't be allowed to transition out of the
init_t domain.

Version-Release number of selected component (if applicable):

How reproducible:
Every time

Steps to Reproduce:
1. from another VM on the same hypervisor run 
iucvconn <target vm> <target terminal>
Actual results:

May 30 10:37:44 zlin1006 kernel: type=1400 audit(1338367064.593:28): avc:  denied  { transition } for  pid=27030 comm="login" path="/lib64/security/pam_krb5/pam_krb5_storetmp" dev=dm-0 ino=137345 scontext=system_u:system_r:init_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=process

Expected results:

Additional info:

As recommended in the iucvtty man-page, I'm starting iucvtty from the inittab (well /etc/init, this is RHEL6)
Comment 1 David Juran 2012-08-01 10:46:05 EDT
Created attachment 601759 [details]
Module that solves the problem

The attached module (mainly by Dan Walsh) solves the problem
Comment 10 errata-xmlrpc 2013-02-21 03:27:23 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.