#109 SELinux denies post-installation process
Closed: Invalid None Opened 17 years ago by couf@fedoraproject.org.

At post-installation phase, a lot of AVC denials happen (SELinux with targeted policy)

They block useradd, rm, pmconv, and some other. This happens a lot and hangs revisor: unable to clean up on exiting -> reboot machine to restore everything.

Some AVC messages:

avc: denied { write } for comm="rm" dev=proc egid=0 euid=0 exe="/bin/rm" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="fd" pid=23026 scontext=user_u:system_r:unconfined_t:s0 sgid=0 subj=user_u:system_r:unconfined_t:s0 suid=0 tclass=dir tcontext=user_u:system_r:unconfined_t:s0 tty=pts1 uid=0

avc: denied { write } for comm="rm" dev=proc egid=0 euid=0 exe="/bin/rm" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="fd" pid=23026 scontext=user_u:system_r:unconfined_t:s0 sgid=0 subj=user_u:system_r:unconfined_t:s0 suid=0 tclass=dir tcontext=system_u:system_r:consolekit_t:s0 tty=pts1 uid=0

avc: denied { write } for comm="rm" dev=proc egid=0 euid=0 exe="/bin/rm" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="attr" pid=23026 scontext=user_u:system_r:unconfined_t:s0 sgid=0 subj=user_u:system_r:unconfined_t:s0 suid=0 tclass=dir tcontext=system_u:system_r:kernel_t:s0 tty=pts1 uid=0

avc: denied { read, write } for comm="useradd" dev=loop0 egid=0 euid=0 exe="/usr/sbin/useradd" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="faillog" pid=22898 scontext=system_u:system_r:useradd_t:s0 sgid=0 subj=system_u:system_r:useradd_t:s0 suid=0 tclass=file tcontext=system_u:object_r:var_log_t:s0 tty=(none) uid=0

avc: denied { read, write } for comm="useradd" dev=loop0 egid=0 euid=0 exe="/usr/sbin/useradd" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="lastlog" pid=22898 scontext=system_u:system_r:useradd_t:s0 sgid=0 subj=system_u:system_r:useradd_t:s0 suid=0 tclass=file tcontext=system_u:object_r:var_log_t:s0 tty=(none) uid=0

avc: denied { read, write } for comm="pwconv" dev=sockfs egid=0 euid=0 exe="/usr/sbin/pwconv" exit=0 fsgid=0 fsuid=0 gid=0 items=0 name="[307626]" path="/var/log/revisor.log" pid=22935 scontext=system_u:system_r:sysadm_passwd_t:s0 sgid=0 subj=system_u:system_r:sysadm_passwd_t:s0 suid=0 tclass=unix_dgram_socket tcontext=system_u:system_r:unconfined_t:s0 tty=(none) uid=0


Metadata Update from @couf@fedoraproject.org:
- Issue assigned to kanarip
- Issue set to the milestone: 2.0.3 Release

8 years ago

Log in to comment on this ticket.

Metadata