Bug 863648 - Munin bind9 plugin prevented to save state by selinux
Summary: Munin bind9 plugin prevented to save state by selinux
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: munin
Version: el6
Hardware: i686
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Kevin Fenzi
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-10-06 09:48 UTC by info
Modified: 2023-09-14 01:37 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2015-03-07 04:34:39 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
audit2allow created .te file (526 bytes, application/octet-stream)
2012-10-06 09:48 UTC, info
no flags Details

Description info 2012-10-06 09:48:55 UTC
Created attachment 622671 [details]
audit2allow created .te file

Description of problem:

Munin bind9 plugin is prevented to save state in /var/lib/munin/plugin-state by selinux.

Version-Release number of selected component (if applicable):

2.0.6-2

How reproducible:

Always.

Steps to Reproduce:
1. yum install munin-node
2. ln -s /usr/share/munin/plugins/bind9 /etc/munin/plugins/bind9
3. service munin-node restart
  
Actual results:

# tail /var/log/munin/munin-node.log
Error output from bind9:
       Cannot open state file at /etc/munin/plugins/bind9 line 66.

Expected results:

No error reported by munin-node.

Additional info, installed munin and selinux packages:

munin-common-2.0.6-2.el6.noarch
munin-node-2.0.6-2.el6.noarch

libselinux-utils-2.0.94-5.3.el6.i686
selinux-policy-targeted-3.7.19-155.el6_3.4.noarch
libselinux-python-2.0.94-5.3.el6.i686
libselinux-2.0.94-5.3.el6.i686
selinux-policy-3.7.19-155.el6_3.4.noarch



I'm attaching a TE file created by audit2allow which seems to fix the issue. As I'm total noob to selinux, I don't know if I should have done something else, because other state files are created okay, only bind9 was denied.

Comment 1 d. johnson 2014-01-01 02:54:38 UTC
Can you verify using munin-2.0.19-1.el6 and selinux-policy-targeted-3.7.19-231.el6.noarch (or newer) ?

This may have been resolved long ago, just need to confirm.

Comment 2 Red Hat Bugzilla 2023-09-14 01:37:51 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days


Note You need to log in before you can comment on or make changes to this bug.