Sshd getting 'dyntransition' AVC's in SElinux enforcing mode

Michael Scherer misc at zarb.org
Fri Dec 27 22:54:11 UTC 2013


Le vendredi 27 décembre 2013 à 15:06 -0700, Philip Prindeville a écrit :
> I’m seeing the following after an update (via yum) from F19 to F20:
> 
> ----
> time->Tue Dec 24 16:05:44 2013
> type=SYSCALL msg=audit(1387926344.492:5867): arch=c000003e syscall=1 success=no exit=-13 a0=6 a1=7f4e5e7afbb0 a2=20 a3=7fff44c2c550 items=0 ppid=686 pid=693 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 ses=4294967295 tty=(none) comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:init_t:s0 key=(null)
> type=AVC msg=audit(1387926344.492:5867): avc:  denied  { dyntransition } for  pid=693 comm="sshd" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:sshd_net_t:s0 tclass=process
> ----
> time->Tue Dec 24 16:05:45 2013
> type=SYSCALL msg=audit(1387926345.093:5883): arch=c000003e syscall=1 success=no exit=-13 a0=7 a1=7f4e5e7acef0 a2=2a a3=666e6f636e753a72 items=0 ppid=686 pid=706 auid=1000 uid=1000 gid=1000 euid=1000 suid=1000 fsuid=1000 egid=1000 sgid=1000 fsgid=1000 ses=627 tty=(none) comm="sshd" exe="/usr/sbin/sshd" subj=system_u:system_r:init_t:s0 key=(null)
> type=AVC msg=audit(1387926345.093:5883): avc:  denied  { dyntransition } for  pid=706 comm="sshd" scontext=system_u:system_r:init_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0 tclass=process
> 
> 
> Is this a known issue?  I’m running:

Can you make sure the label is correct on the fs ( ie, relabel the
whole / ), as this seems to be a wrongly labeled sshd.

-- 
Michael Scherer



More information about the devel mailing list