Linux-audit Archive on lore.kernel.org
 help / color / mirror / Atom feed
* Possibly wrong audit messages
@ 2006-06-12 12:36 Glauber de Oliveira Costa
  2006-06-12 12:51 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Glauber de Oliveira Costa @ 2006-06-12 12:36 UTC (permalink / raw)
  To: linux-audit, sgrubb, mcthomps

Hi,

I'm in a FC5 box, and tryied to shoot an setsebool command as 
secadm_r:SystemHigh (mls policy)

Instead of an audit message identifying the set operation, I'm getting 81 AVC 
messages (81 is the number of booleans present in /selinux/booleans/) 
indicating a success. Such a large number of messages makes the correct 
information hard to find, IMHO. This does not seem to be the right behaviour 
to me.

A typical message looks like this:
 
type=AVC msg=audit(1149411239.670:6462): avc:  granted  { setbool } 
for pid=3460 comm="setsebool" scontext=root:secadm_r:secadm_t:s15:c0.c255
tcontext=system_u:object_r:security_t:s15:c0.c255 tclass=security

If this is really the expected behaviour, sorry for the bogus report. 

-- 
"Free as in Freedom"
Glauber de Oliveira Costa

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2006-06-12 12:51 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-12 12:36 Possibly wrong audit messages Glauber de Oliveira Costa
2006-06-12 12:51 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox