From mboxrd@z Thu Jan 1 00:00:00 1970 From: Daniel J Walsh Subject: Re: restorecon resets files Date: Mon, 06 Oct 2008 16:05:02 -0400 Message-ID: <48EA6F6E.70508@redhat.com> References: <1223301787.15037.228.camel@homeserver> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <1223301787.15037.228.camel@homeserver> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: LC Bruzenak Cc: Linux Audit List-Id: linux-audit@redhat.com LC Bruzenak wrote: > # ls -Z /var/run/auditd.pid /var/run/audispd_events > srw-r----- root root system_u:object_r:audisp_var_run_t:SystemHigh /var/run/audispd_events > -rw-r--r-- root root system_u:object_r:auditd_var_run_t:SystemHigh /var/run/auditd.pid > > # restorecon -rv /var/run/ > restorecon reset /var/run/audispd_events context system_u:object_r:audisp_var_run_t:s15:c0.c1023->system_u:object_r:audisp_var_run_t:s0 > restorecon reset /var/run/auditd.pid context system_u:object_r:auditd_var_run_t:s15:c0.c1023->system_u:object_r:auditd_var_run_t:s0 > > [root@hugo ~]# ls -Z /var/run/auditd.pid /var/run/audispd_events > srw-r----- root root system_u:object_r:audisp_var_run_t:SystemLow /var/run/audispd_events > -rw-r--r-- root root system_u:object_r:auditd_var_run_t:SystemLow /var/run/auditd.pid > > I assume that both these files should be kept at SystemHigh? > > selinux-policy-mls-3.4.2-14.fc9.noarch > > Thx, > LCB. > Yes that is a bug.