Bug 861980 - selinux, afs, and readahead
selinux, afs, and readahead
Status: CLOSED ERRATA
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
6.3
All Linux
unspecified Severity low
: rc
: ---
Assigned To: Miroslav Grepl
Milos Malik
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2012-10-01 09:51 EDT by jcpunk
Modified: 2013-02-21 03:31 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2013-02-21 03:31:01 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description jcpunk 2012-10-01 09:51:07 EDT
Description of problem:
The following audit message is sometimes generated on my system.

avc:  denied  { search } for  pid=381 comm="readahead-colle" name="openafs" dev=proc ino=4026532214 scontext=system_u:system_r:readahead_t:s0 tcontext=system_u:object_r:proc_afs_t:s0 tclass=dir

I'm not 100% sure that readahead should be assisting with these reads.

Version-Release number of selected component (if applicable): selinux-policy-targeted-3.7.19-155.el6_3.4.noarch.rpm


How reproducible: 50%


Steps to Reproduce:
1. load afs
2. browse around a bit
3. set a home dir to afs space
4. reboot
5. login as user from #3
6. check audit log for errors
  
Actual results:
errors in audit log

Expected results:
no audit log errors

Additional info:
The selinux package provides a number of policy componants for afs.
policy/modules/services/afs.if
policy/modules/services/afs.te
policy/modules/kernel/kernel.te
policy/modules/kernel/kernel.if
policy/modules/kernel/filesystem.te
man/man8/afs_selinux.8
Comment 2 Daniel Walsh 2012-10-08 16:31:43 EDT
I don't see any problem with allowing readahead to list all of proc.

Just added fix for RHEL7/F18
Comment 7 errata-xmlrpc 2013-02-21 03:31:01 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

http://rhn.redhat.com/errata/RHBA-2013-0314.html

Note You need to log in before you can comment on or make changes to this bug.