From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: watching files in selinuxfs Date: Thu, 28 Sep 2006 16:33:58 -0400 Message-ID: <200609281633.59001.sgrubb@redhat.com> References: Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Wednesday 27 September 2006 17:26, Debora Velarde wrote: > When in enforcing mode, I am only able to audit files in selinuxfs by > inode, not by path. =A0 =A0I am running as auditadm_r. > > /* Try adding audit rule with -F path */ > # auditctl -a exit,always -S open -F path=3D/selinux/enforce > Error sending add rule request (Permission denied) When I do this command, I see AVC's: time->Thu Sep 28 16:25:12 2006 type=3DAVC msg=3Daudit(1159475112.366:289): avc: denied { getattr } for= =20 pid=3D12893 comm=3D"auditctl" name=3D"/" dev=3Dhda7 ino=3D2=20 scontext=3Droot:system_r:auditctl_t:s0-s0:c0.c255=20 tcontext=3Dsystem_u:object_r:fs_t:s0 tclass=3Dfilesystem allow auditctl_t fs_t:filesystem getattr; allow auditctl_t security_t:dir search; -Steve