From: Timothy Wood <timothy@hallcomp.com>
To: SELinux <SELinux@tycho.nsa.gov>
Subject: Wierdness with lsm 2.5
Date: 10 Jul 2002 10:04:04 -0400 [thread overview]
Message-ID: <1026309847.9320.67.camel@phobos> (raw)
Has anyone been using the 2.5 lsm since the last release? I'm getting a
whole lot of errors the 2.4 never gave me. Here are some of them.
-----md errors------
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md0
dev=03:03 ino=66778 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md10
dev=03:03 ino=65551 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md0
dev=03:03 ino=66778 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md1
dev=03:03 ino=65550 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md2
dev=03:03 ino=66782 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md3
dev=03:03 ino=66792 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md4
dev=03:03 ino=66794 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md5
dev=03:03 ino=65554 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md6
dev=03:03 ino=65555 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/md7
dev=03:03 ino=65556 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
AVC: 501642 messages suppressed.
--------some wierd device -----------
(new thing in 2.5 kernel I guess, disks of some sort or another)
avc: denied { getattr } for pid=121 exe=/sbin/fsck
path=/dev/cciss/c2d4p14 dev=03:03 ino=2425518
scontext=system_u:system_r:fsadm_t tcontext=system_u:object_r:device_t
tclass=blk_file
avc: denied { getattr } for pid=121 exe=/sbin/fsck
path=/dev/cciss/c4d10p6 dev=03:03 ino=2425893
scontext=system_u:system_r:fsadm_t tcontext=system_u:object_r:device_t
tclass=blk_file
AVC: 626927 messages suppressed.
avc: denied { getattr } for pid=121 exe=/sbin/fsck
path=/dev/cciss/c6d2p7 dev=03:03 ino=2426517
scontext=system_u:system_r:fsadm_t tcontext=system_u:object_r:device_t
tclass=blk_file
AVC: 627109 messages suppressed.
avc: denied { getattr } for pid=121 exe=/sbin/fsck path=/dev/hitcd
dev=03:03 ino=66633 scontext=system_u:system_r:fsadm_t
tcontext=system_u:object_r:device_t tclass=blk_file
-------some other wierd thing.
avc: denied { sys_tty_config } for pid=721 comm=sh capability=26
scontext=system_u:system_r:checkpc_t
tcontext=system_u:system_r:checkpc_t tclass=capability
There are several other "messages suppressed" messages and several other
things on the system that do not work. for example I have two
partitions on this test machine, a /boot and a /. The / mounts fine but
the /boot won't mount.
Does anyone know off the top of their head what the /dev/cciss is for?
I see a lot of disk devices noted in a solaris fashion (eg c0d0p0s2 etc
etc instead of hda1 hda2 etc etc)
Any thoughts welcome.
Timothy,
BTW, I did install this overtop of my lsm2.4 so that maybe messed it up?
--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
next reply other threads:[~2002-07-10 14:04 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2002-07-10 14:04 Timothy Wood [this message]
2002-07-10 14:40 ` Wierdness with lsm 2.5 Stephen Smalley
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1026309847.9320.67.camel@phobos \
--to=timothy@hallcomp.com \
--cc=SELinux@tycho.nsa.gov \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.