From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: auditd shutdown issue Date: Mon, 7 May 2007 12:12:52 -0400 Message-ID: <200705071212.52354.sgrubb@redhat.com> References: <20070507151806.GA17862@sgi.com> <20070507155655.GA18147@sgi.com> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <20070507155655.GA18147@sgi.com> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com On Monday 07 May 2007 11:56, Bill O'Donnell wrote: > Stopping auditd:audit(1178276231.766:704): avc: =A0denied =A0{ write } = for > pid=3D2911 comm=3D"auditd" name=3D"log" dev=3Dtmpfs ino=3D10195 > scontext=3Dsystem_u:system_r:auditd_t:s0 > tcontext=3Dsystem_u:object_r:device_t:s0 tclass=3Dsock_file=20 This would seem to indicate you have a mislabeled system. You should not = have=20 a label of device_t type unless you have hardware we've not seen. Without= =20 knowing more about how you got in this situation, its hard to say exactly= =20 what the problem is. I'd start by relabeling your system. -Steve