All of lore.kernel.org
 help / color / mirror / Atom feed
From: dE <de.techno@gmail.com>
To: selinux@tycho.nsa.gov
Subject: Re: Weird un-audited denial on tmp_t
Date: Wed, 02 Jul 2014 09:38:41 +0530	[thread overview]
Message-ID: <53B385C9.7000904@gmail.com> (raw)
In-Reply-To: <d66c6965-1f79-42fe-8a91-359fd22e71f9@email.android.com>

[-- Attachment #1: Type: text/plain, Size: 1372 bytes --]

On 07/01/14 22:43, David wrote:
> Sorry, I know this isn't fedora (CentOS 5 actually) but I believe this
> may be a more generic situation.
>
> I recently was trying to troubleshoot an issue where a process spawned
> off under the dovecot_t process type and needed to create files under /tmp
> (tmp_t).
>
> This wasn't obvious as there where no denial messages in audit for
> tmp_t.  Even using "semodule -DB" didn't show denial messages.  All I
> knew was the process was trying to read/write files and was getting
> access denied.  I just didn't know where or why.
>
> Eventually an strace on the process tree showed the access attempt to
> /tmp.  Since I knew policy would be required to create tmp types I went
> ahead and added tmp file transitions and appropriate supporting
> permissions around the new dovecot_tmp_t type.  This fixed the problem.
>
> What is surprising to me is that there were no denial messages related
> to tmp_t or dovecot_t.  Nothing, regardless of permissive vs enforcing,
> or semodule -DB set.
>
> Any clue as to why this wouldn't trigger a log message?
>
> This is a strict, not targeted policy, yes I know very old school.
>
> Thanks,
> David
>
> --
> selinux mailing list
> selinux@lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/selinux

After you've removed all dontaudits, does seinfo shows any Dontaudit?

[-- Attachment #2: Type: text/html, Size: 2259 bytes --]

           reply	other threads:[~2014-07-02  4:12 UTC|newest]

Thread overview: expand[flat|nested]  mbox.gz  Atom feed
 [parent not found: <d66c6965-1f79-42fe-8a91-359fd22e71f9@email.android.com>]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53B385C9.7000904@gmail.com \
    --to=de.techno@gmail.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.