Summary: | dmesg wants to read/write /dev/console while still device_t labeled | ||
---|---|---|---|
Product: | Gentoo Linux | Reporter: | Sven Vermeulen (RETIRED) <swift> |
Component: | Hardened | Assignee: | Sven Vermeulen (RETIRED) <swift> |
Status: | VERIFIED FIXED | ||
Severity: | normal | CC: | selinux |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | sec-policy r11 | ||
Package list: | Runtime testing required: | --- |
Description
Sven Vermeulen (RETIRED)
2012-05-28 08:39:29 UTC
Will be dontaudit'ed in r11 AVC denials shown: """ [ 3.247401] type=1400 audit(1338194354.246:5): avc: denied { read write } for pid=997 comm="dmesg" name="console" dev="devtmpfs" ino=1035 scontext=system_u:system_r:dmesg_t tcontext=system_u:object_r:device_t tclass=chr_file [ 3.260807] type=1400 audit(1338194354.259:6): avc: denied { read write } for pid=997 comm="dmesg" path="/dev/console" dev="devtmpfs" ino=1035 scontext=system_u:system_r:dmesg_t tcontext=system_u:object_r:device_t tclass=chr_file [ 3.268971] type=1400 audit(1338194354.267:7): avc: denied { read write } for pid=997 comm="dmesg" path="/dev/console" dev="devtmpfs" ino=1035 scontext=system_u:system_r:dmesg_t tcontext=system_u:object_r:device_t tclass=chr_file [ 3.273404] type=1400 audit(1338194354.272:8): avc: denied { read write } for pid=997 comm="dmesg" path="/dev/console" dev="devtmpfs" ino=1035 scontext=system_u:system_r:dmesg_t tcontext=system_u:object_r:device_t tclass=chr_file """ In hardened-dev overlay, rev 11 In main tree, ~arch'ed Stabilized |