From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: audit 1.2.2 released Date: Tue, 16 May 2006 11:34:29 -0400 Message-ID: <200605161134.29407.sgrubb@redhat.com> References: <200605121726.32952.sgrubb@redhat.com> <4468E115.40107@us.ibm.com> <4469E753.3070206@us.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <4469E753.3070206@us.ibm.com> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Michael C Thompson Cc: Linux Audit List-Id: linux-audit@redhat.com On Tuesday 16 May 2006 10:53, Michael C Thompson wrote: > > [ resulting log activity: > > type=3DAVC msg=3Daudit(1147657744.953:39): avc: =A0denied =A0{ nlmsg_= readpriv } > > for =A0pid=3D2091 comm=3D"auditctl" > > scontext=3Droot:staff_r:staff_t:s0-s15:c0.c255 > > tcontext=3Droot:staff_r:staff_t:s0-s15:c0.c255 tclass=3Dnetlink_audit= _socket > > type=3DSYSCALL msg=3Daudit(1147657744.953:39): arch=3D40000003 syscal= l=3D102 > > success=3Dyes exit=3D16 a0=3Db a1=3Dbfad2760 a2=3D805b0f8 a3=3D10 ite= ms=3D0 ppid=3D2067 > > pid=3D2091 auid=3D0 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D= 0 sgid=3D0 fsgid=3D0 > > tty=3Dpts1 comm=3D"auditctl" exe=3D"/sbin/auditctl" > > subj=3Droot:staff_r:staff_t:s0-s15:c0.c255 > > type=3DSOCKADDR msg=3Daudit(1147657744.953:39): > > saddr=3D100000000000000000000000 type=3DSOCKETCALL > > msg=3Daudit(1147657744.953:39): nargs=3D6 a0=3D3 a1=3Dbfad69fc a2=3D1= 0 a3=3D0 > > a4=3Dbfad2790 a5=3Dc > > ] I missed this. This is the smoking gun...why did SE Linux reject the sysc= all?=20 Next time, SE Linux was OK and allowed access. I wonder if this points to= an=20 avc caching problem since subsequent attempts is just fine. -Steve