All of lore.kernel.org
 help / color / mirror / Atom feed
* AVC: IPv6 problems
@ 2007-05-22 18:22 Stefan Schulze Frielinghaus
  2007-05-22 19:24 ` Paul Moore
  0 siblings, 1 reply; 7+ messages in thread
From: Stefan Schulze Frielinghaus @ 2007-05-22 18:22 UTC (permalink / raw)
  To: SELinux List

Hello,

periodically I receive the following AVC denial:

audit(1179815459.477:213): avc:  denied  { rawip_send } for   
saddr=fe80:0000:0000:0000:0211:d8ff:feea:XXXX  
daddr=fe80:0000:0000:0000:0211:24ff:fee1:YYYY netif=eth0  
scontext=system_u:system_r:kernel_t:s15:c0.c255  
tcontext=system_u:object_r:link_local_node_t:s0 tclass=node

My local rule-set:

allow kernel_t link_local_node_t:node rawip_send;
# another AVC denial which often raises up
allow kernel_t compat_ipv4_node_t:node rawip_send;

The rules seem to be ignored. Every day I receive some of the  
mentioned AVC denials despite the fact that the TE rules are loaded.  
Is this a known problem with IPv6 traffic in LANs? Is there even a  
solution out?

Best regards,
Stefan

PS: I'm using Debian (etch) with refpolicy-20061212.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2007-05-24 13:54 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-22 18:22 AVC: IPv6 problems Stefan Schulze Frielinghaus
2007-05-22 19:24 ` Paul Moore
2007-05-23 12:21   ` Stefan Schulze Frielinghaus
2007-05-23 13:08     ` Daniel J Walsh
2007-05-23 13:27     ` Paul Moore
2007-05-24  5:04       ` Stefan Schulze Frielinghaus
2007-05-24 13:53         ` Paul Moore

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.