Project

General

Profile

Actions

Bug #4458

closed

AVC denials aboutname="online" dev=sysfs ino=23 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file

Added by Jan Pazdziora about 10 years ago. Updated about 10 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

Installing Foreman nightly from

baseurl=http://yum.theforeman.org/nightly/el6/$basearch

on RHEL 6.5 causes AVC denials to eventually show up in the audit.log:

type=AVC msg=audit(1393403231.005:232): avc:  denied  { search } for  pid=23349 comm="ps" name="/" dev=sysfs ino=1 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=dir
type=AVC msg=audit(1393403231.005:232): avc:  denied  { read } for  pid=23349 comm="ps" name="online" dev=sysfs ino=23 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file
type=AVC msg=audit(1393403231.005:232): avc:  denied  { open } for  pid=23349 comm="ps" name="online" dev=sysfs ino=23 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file
type=AVC msg=audit(1393403409.342:248): avc:  denied  { search } for  pid=23695 comm="PassengerHelper" name="/" dev=sysfs ino=1 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=dir
type=AVC msg=audit(1393403409.342:248): avc:  denied  { read } for  pid=23695 comm="PassengerHelper" name="online" dev=sysfs ino=23 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file
type=AVC msg=audit(1393403409.342:248): avc:  denied  { open } for  pid=23695 comm="PassengerHelper" name="online" dev=sysfs ino=23 scontext=unconfined_u:system_r:passenger_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=file

The file (path) in question is /sys/devices/system/cpu/online.


Related issues 1 (0 open1 closed)

Is duplicate of SELinux - Bug #3465: AVC denials with Foreman 1.3 on RHEL 6ClosedLukas Zapletal10/22/2013Actions
Actions

Also available in: Atom PDF