Fedora 16 AVC at boot time

David Highley dhighley at highley-recommended.com
Thu Jan 26 04:33:04 UTC 2012


"Daniel J Walsh wrote:"
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
> 
> On 01/25/2012 01:38 PM, David Highley wrote:
> > "Daniel J Walsh wrote:"
> >> 
> > On 01/24/2012 10:39 PM, David Highley wrote:
> >>>> time->Tue Jan 24 06:17:02 2012 type=SYSCALL 
> >>>> msg=audit(1327414622.867:2517): arch=c000003e syscall=59 
> >>>> success=yes exit=0 a0=9669f0 a1=cc8170 a2=7fff1bf396c8 a3=1f 
> >>>> items=0 ppid=5248 pid=5253 auid=0 uid=0 gid=0 euid=0 suid=0
> >>>> fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=293 comm="sh"
> >>>> exe="/bin/bash" 
> >>>> subj=unconfined_u:system_r:rpm_script_t:s0-s0:c0.c1023
> >>>> key=(null) type=AVC msg=audit(1327414622.867:2517): avc:
> >>>> denied  { transition } for  pid=5253 comm="rpm"
> >>>> path="/bin/bash" dev=dm-1 ino=393240 
> >>>> scontext=unconfined_u:system_r:bootloader_t:s0-s0:c0.c1023 
> >>>> tcontext=unconfined_u:system_r:rpm_script_t:s0-s0:c0.c1023 
> >>>> tclass=process ---- time->Tue Jan 24 06:23:38 2012
> >>>> type=SYSCALL msg=audit(1327415018.410:38): arch=c000003e
> >>>> syscall=2 success=no exit=-13 a0=7fff0fc10e50 a1=0
> >>>> a2=7fff0fc10e79 a3=68 items=0 ppid=1180 pid=1359
> >>>> auid=4294967295 uid=0 gid=48 euid=0 suid=0 fsuid=0 egid=48
> >>>> sgid=48 fsgid=48 tty=(none) ses=4294967295 
> >>>> comm="/usr/sbin/httpd" exe="/usr/sbin/httpd" 
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC 
> >>>> msg=audit(1327415018.410:38): avc:  denied  { search } for 
> >>>> pid=1359 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.410:39): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1360 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.410:39): avc:  denied  { search } for 
> >>>> pid=1360 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.411:40): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1361 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.411:40): avc:  denied  { search } for 
> >>>> pid=1361 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.411:41): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1362 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.411:41): avc:  denied  { search } for 
> >>>> pid=1362 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.414:42): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1365 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.414:42): avc:  denied  { search } for 
> >>>> pid=1365 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.414:43): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1364 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.414:43): avc:  denied  { search } for 
> >>>> pid=1364 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.415:44): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1366 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.415:44): avc:  denied  { search } for 
> >>>> pid=1366 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.416:45): arch=c000003e syscall=2
> >>>> success=no exit=-13 a0=7fff0fc10e50 a1=0 a2=7fff0fc10e79
> >>>> a3=68 items=0 ppid=1180 pid=1363 auid=4294967295 uid=0 gid=48
> >>>> euid=0 suid=0 fsuid=0 egid=48 sgid=48 fsgid=48 tty=(none)
> >>>> ses=4294967295 comm="/usr/sbin/httpd" exe="/usr/sbin/httpd"
> >>>> subj=system_u:system_r:httpd_t:s0 key=(null) type=AVC
> >>>> msg=audit(1327415018.416:45): avc:  denied  { search } for 
> >>>> pid=1363 comm="/usr/sbin/httpd" name="yp" dev=dm-1
> >>>> ino=1313161 scontext=system_u:system_r:httpd_t:s0 
> >>>> tcontext=system_u:object_r:var_yp_t:s0 tclass=dir ----
> >>>> time->Tue Jan 24 06:23:38 2012 type=SYSCALL
> >>>> msg=audit(1327415018.418:46): arch=c000003e syscall=42
> >>>> success=no exit=-13 a0=3 a1=7fff071131f0 a2=10 a3=98 items=0
> >>>> ppid=1367 pid=1369 auid=4294967295 uid=81 gid=81 euid=0
> >>>> suid=0 fsuid=0 egid=81 sgid=81 fsgid=81 tty=(none) 
> >>>> ses=4294967295 comm="dbus-daemon-lau" 
> >>>> exe="/lib64/dbus-1/dbus-daemon-launch-helper" 
> >>>> subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023
> >>>> key=(null) type=AVC msg=audit(1327415018.418:46): avc:
> >>>> denied  { name_connect } for  pid=1369 comm="dbus-daemon-lau"
> >>>> dest=111 
> >>>> scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 
> >>>> tcontext=system_u:object_r:portmap_port_t:s0
> >>>> tclass=tcp_socket ---- time->Tue Jan 24 06:23:38 2012
> >>>> type=SYSCALL msg=audit(1327415018.418:47): arch=c000003e
> >>>> syscall=49 success=no exit=-13 a0=3 a1=7fff07112f60 a2=10
> >>>> a3=98 items=0 ppid=1367 pid=1369 auid=4294967295 uid=81
> >>>> gid=81 euid=0 suid=0 fsuid=0 egid=81 sgid=81 fsgid=81
> >>>> tty=(none) ses=4294967295 comm="dbus-daemon-lau" 
> >>>> exe="/lib64/dbus-1/dbus-daemon-launch-helper" 
> >>>> subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023
> >>>> key=(null) type=AVC msg=audit(1327415018.418:47): avc:
> >>>> denied  { name_bind } for  pid=1369 comm="dbus-daemon-lau"
> >>>> src=697 
> >>>> scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 
> >>>> tcontext=system_u:object_r:hi_reserved_port_t:s0
> >>>> tclass=tcp_socket ---- time->Tue Jan 24 06:23:38 2012
> >>>> type=SYSCALL msg=audit(1327415018.418:48): arch=c000003e
> >>>> syscall=42 success=no exit=-13 a0=3 a1=7fff071131f0 a2=10
> >>>> a3=98 items=0 ppid=1367 pid=1369 auid=4294967295 uid=81
> >>>> gid=81 euid=0 suid=0 fsuid=0 egid=81 sgid=81 fsgid=81
> >>>> tty=(none) ses=4294967295 comm="dbus-daemon-lau" 
> >>>> exe="/lib64/dbus-1/dbus-daemon-launch-helper" 
> >>>> subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023
> >>>> key=(null) type=AVC msg=audit(1327415018.418:48): avc:
> >>>> denied  { name_connect } for  pid=1369 comm="dbus-daemon-lau"
> >>>> dest=111 
> >>>> scontext=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 
> >>>> tcontext=system_u:object_r:portmap_port_t:s0
> >>>> tclass=tcp_socket
> > 
> > Do you have the allow_ypbind boolean permanantly turned on
> > 
> > setsebool -P allow_ypbind 1
> > 
> >> Yes, we permanently set this bool.
> > 
> > If the init script is turning it on, you could see avc's like
> > this.
> > 
> > Have no idea what the bootloader->rpm_script one is.
> > 
> > There used to be some kernel update scripts that were labeled as 
> > bootloader_exec_t?
> >> 
> > -- selinux mailing list selinux at lists.fedoraproject.org 
> > https://admin.fedoraproject.org/mailman/listinfo/selinux
> 
> Strange and these happen on every boot, and then stop?

Just tried another reboot and got the same results so I would say that
it happens on every boot.

> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.11 (GNU/Linux)
> Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
> 
> iEYEARECAAYFAk8gXiIACgkQrlYvE4MpobMCQgCeNQgkkaZ2sMY0ZoR+UuS+xiSH
> dMwAn3XdqXX3VCqrpX+2ns5NizThEeW3
> =xlB4
> -----END PGP SIGNATURE-----
> 


More information about the selinux mailing list