All of lore.kernel.org
 help / color / mirror / Atom feed
* AVC for unlabeled_t on cgroup
@ 2013-07-11 18:38 Andy Ruch
  2013-07-11 19:06 ` Stephen Smalley
  2013-07-13 17:48 ` Sven Vermeulen
  0 siblings, 2 replies; 6+ messages in thread
From: Andy Ruch @ 2013-07-11 18:38 UTC (permalink / raw)
  To: SELinux ML

[-- Attachment #1: Type: text/plain, Size: 983 bytes --]

Hello,

I'm implementing a restrictive policy for RHEL 6.3 based on CLIP. I've enabled the cgroup module but I'm still seeing the AVC below. This is just one of a dozen similar AVC's for different inodes. When I look at the /cgroup after the system boots, everything has a cgroup_t label. Where would the unlabeled_t be coming from?



type=SYSCALL msg=audit(07/11/2013 17:25:38.885:7) : arch=x86_64 syscall=mount success=yes exit=0 a0=7f57846ac4c1 a1=7f57848b03c0 a2=7f57846ac4c1 a3=0 items=0 ppid=1177 pid=1178 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=cgconfigparser exe=/sbin/cgconfigparser subj=system_u:system_r:cgconfig_t:s0 key=(null) 

type=AVC msg=audit(07/11/2013 17:25:38.885:7) : avc:  denied  { search } for  pid=1178 comm=cgconfigparser name=/ dev=cgroup ino=12518 scontext=system_u:system_r:kernel_t:s0 tcontext=system_u:object_r:unlabeled_t:s0 tclass=dir 


Thanks,
Andrew Ruch

[-- Attachment #2: Type: text/html, Size: 1894 bytes --]

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2013-07-15 13:07 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-07-11 18:38 AVC for unlabeled_t on cgroup Andy Ruch
2013-07-11 19:06 ` Stephen Smalley
2013-07-11 19:24   ` Andy Ruch
2013-07-11 19:38     ` Stephen Smalley
2013-07-13 17:48 ` Sven Vermeulen
2013-07-15 13:07   ` Stephen Smalley

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.