All of lore.kernel.org
 help / color / mirror / Atom feed
* [refpolicy] unexpected AVC. how to dig deeper?
@ 2013-12-19 15:02 Pierre Ossman
  2013-12-19 16:10 ` Daniel J Walsh
  0 siblings, 1 reply; 3+ messages in thread
From: Pierre Ossman @ 2013-12-19 15:02 UTC (permalink / raw)
  To: refpolicy

Hi,

I'm having problems with this AVC on RHEL6:

type=AVC msg=audit(1387461339.290:123): avc:  denied  { transition } for  pid=2548 comm="tl-session" path="/opt/thinlinc/libexec/tl-xinit" dev=dm-0 ino=789253 scontext=unconfined_u:system_r:thinlinc_session_t:s0 tcontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tclass=process

I'm at a loss to why though as I have this in my policy:

	userdom_spec_domtrans_all_users(thinlinc_session_t)

I even checked that the temporary file got an appropriate allow rule:

        allow thinlinc_session_t userdomain:process transition;

I need some help in debugging this further. What could prevent this
allow line from being respected?

Rgds
-- 
Pierre Ossman           Software Development
Cendio AB		http://cendio.com
Teknikringen 8		http://twitter.com/ThinLinc
583 30 Link?ping	http://facebook.com/ThinLinc
Phone: +46-13-214600	http://plus.google.com/+CendioThinLinc

A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 198 bytes
Desc: not available
Url : http://oss.tresys.com/pipermail/refpolicy/attachments/20131219/227ecf4b/attachment.bin 

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2013-12-19 20:17 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-12-19 15:02 [refpolicy] unexpected AVC. how to dig deeper? Pierre Ossman
2013-12-19 16:10 ` Daniel J Walsh
2013-12-19 20:17   ` Pierre Ossman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.