Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 449268 - Reloading SELinux policy gives lots of selinux_audit_rule_match
Summary: Reloading SELinux policy gives lots of selinux_audit_rule_match
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Hardened (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Sven Vermeulen (RETIRED)
URL:
Whiteboard: integrity
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-30 08:43 UTC by Sven Vermeulen (RETIRED)
Modified: 2013-08-27 17:39 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sven Vermeulen (RETIRED) gentoo-dev 2012-12-30 08:43:48 UTC
After reloading the policy (semodule -B), the audit logs (and dmesg) is flooded with:

"""
[  331.491062] type=1401 audit(1356856723.741:86): selinux_audit_rule_match: stale rule
[  331.491062] 
"""

This keeps on coming until a reboot is done.

Reproducible: Always
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2012-12-30 09:53:39 UTC
I have the same with IMA in-kernel, but appraisal disabled through the command-line (ima_appraise=off) and IMA auditing off (ima_audit=0)
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2013-01-19 21:28:03 UTC
Fixed with the patch mentioned, waiting until it is upstreamed
Comment 4 Sven Vermeulen (RETIRED) gentoo-dev 2013-08-27 17:39:55 UTC
Has been committed to main kernel tree in january, but needed an additional fix that is now in 3.4+ kernels.