Bug 893096 - Starting rhnmd on RHEL7 produces AVC denial
Summary: Starting rhnmd on RHEL7 produces AVC denial
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Satellite 5
Classification: Red Hat
Component: Client
Version: 550
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Michael Mráka
QA Contact: Martin Minar
URL:
Whiteboard:
Depends On:
Blocks: sat570-lowbug
TreeView+ depends on / blocked
 
Reported: 2013-01-08 15:14 UTC by Tomáš Kašpárek
Modified: 2016-07-04 00:57 UTC (History)
3 users (show)

Fixed In Version: rhnmd-5.3.17-2
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-01-13 09:45:18 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Tomáš Kašpárek 2013-01-08 15:14:35 UTC
Description of problem:
rhnmd sometimes produces following AVC denial when starting on RHEL7

Version-Release number of selected component (if applicable):
spacewalk 1.9 nightly, RHEL7 client

How reproducible:
non-determistic

Steps to Reproduce:
1. # service rhnmd start && service rhnmd stop
  
Actual results:
AVC denial
type=AVC msg=audit(1357652638.535:481): avc: denied { name_bind } for pid=5668 comm="rhnmd" src=4545 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket 

Expected results:
no AVC denials

Additional info:

Comment 1 Michael Mráka 2013-07-29 12:46:58 UTC
Fixed in spacewalk nightly by

commit 735a8220c954186373fcf4c640002c513df84673
    893096 - bind rhnmd to port on new RHEL
    fixing
    type=AVC msg=audit(1375100630.341:771): avc:  denied  { name_bind } for pid=19076 comm="rhnmd" src=4545 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=tcp_socket

Comment 2 Michael Mráka 2013-07-29 12:50:25 UTC
Backported to SATELLITE-5.6 as
commit 66a3dfd3ff28d306fda23841e3a86187a48a87bf
    893096 - bind rhnmd to port on new RHEL

Comment 6 Clifford Perry 2014-10-06 16:04:24 UTC
resetting for fresh review. Doubt modified is correct state.

Comment 7 Clifford Perry 2015-01-13 09:45:18 UTC
With the release of Red Hat Satellite 5.7 on January 12th 2015 this bug is being moved to a Closed Current Release state. 

The Satellite 5.7 GA Errata:
 - https://rhn.redhat.com/errata/RHSA-2015-0033.html 

Satellite 5.7 Release Notes:
 - https://access.redhat.com/documentation/en-US/Red_Hat_Satellite/5.7/html-single/Release_Notes/index.html

Satellite Customer Portal Blog announcement for release:
 - https://access.redhat.com/blogs/1169563/posts/1315743 

NOTE: This specific bug did not get verified and being closed as assumed fixed. Please reopen if this is not resolved within the release. 

Cliff


Note You need to log in before you can comment on or make changes to this bug.