avc messages corrupted?

Tom London selinux at gmail.com
Sat Apr 23 20:54:46 UTC 2005


Running targeted/enforcing, latest rawhide (.1261)

Examining /var/log/messages, I notice some 'corrupted' avc messages, e.g.:

Apr 23 13:05:33 localhost kernel: audit(1114286729.835:0): avc: 
denied  { search } for  name=3228 dev=proc ino=211550210
scontext=system_u:system_r:initss=dir

Apr 23 13:06:31 localhost kernel: audit(1114286790.120:0): avc: 
denied  { search } for  name=3228 dev=proc ino=211550210
scontext=system_u:system_r:i127:0): avc:  denied  { search } for 
name=1780 dev=proc ino=116654082 scontext=system_u:system_r:init_t
tcontext=system_u:system_r:kernel_t tclass=dir

Apr 23 13:06:41 localhost kernel: audit(1114286800.202:0): avc: 
denied  { search } for  name=3 dev=proc ino=196610
scontext=system_u:system_r:inystem_r:init_t
tcontext=system_u:system_r:kernel_t tclass=dir

[initss? i127? inystem?  there are more....]

Is there a lock problem with auditing?
tom
-- 
Tom London




More information about the selinux mailing list