F-12 arpwatch AVCs

Daniel J Walsh dwalsh at redhat.com
Mon Nov 23 23:40:50 UTC 2009


On 11/23/2009 04:28 PM, Paul Howarth wrote:
> Just updated my DHCP/arpwatch box to F-12 and needed to add this to
> local policy:
> 
> kernel_read_network_state(arpwatch_t)
> 
> AVCs:
> 
> type=AVC msg=audit(1258984783.886:788): avc:  denied  { read } for  pid=4592 comm="arpwatch" name="dev" dev=proc ino=4026531931 scontext=unconfined_u:system_r:arpwatch_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=file
> type=SYSCALL msg=audit(1258984783.886:788): arch=c000003e syscall=2 success=no exit=-13 a0=3e9aa1f9d5 a1=0 a2=1b6 a3=0 items=0 ppid=1 pid=4592 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="arpwatch" exe="/usr/sbin/arpwatch" subj=unconfined_u:system_r:arpwatch_t:s0 key=(null)
> type=SYSCALL msg=audit(1258984783.894:789): arch=c000003e syscall=54 success=yes exit=0 a0=0 a1=107 a2=1 a3=7fff6c6ebff0 items=0 ppid=1 pid=4592 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="arpwatch" exe="/usr/sbin/arpwatch" subj=unconfined_u:system_r:arpwatch_t:s0 key=(null)
> type=AVC msg=audit(1259008591.308:107843): avc:  denied  { read } for  pid=4085 comm="arpwatch" name="dev" dev=proc ino=4026531931 scontext=unconfined_u:system_r:arpwatch_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=file
> type=AVC msg=audit(1259008591.308:107843): avc:  denied  { open } for  pid=4085 comm="arpwatch" name="dev" dev=proc ino=4026531931 scontext=unconfined_u:system_r:arpwatch_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=file
> type=SYSCALL msg=audit(1259008591.308:107843): arch=c000003e syscall=2 success=yes exit=0 a0=3e9aa1f9d5 a1=0 a2=1b6 a3=0 items=0 ppid=1 pid=4085 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="arpwatch" exe="/usr/sbin/arpwatch" subj=unconfined_u:system_r:arpwatch_t:s0 key=(null)
> type=AVC msg=audit(1259008591.308:107844): avc:  denied  { getattr } for  pid=4085 comm="arpwatch" path="/proc/4085/net/dev" dev=proc ino=4026531931 scontext=unconfined_u:system_r:arpwatch_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=file
> type=SYSCALL msg=audit(1259008591.308:107844): arch=c000003e syscall=5 success=yes exit=0 a0=0 a1=7fff01307210 a2=7fff01307210 a3=7fff01307110 items=0 ppid=1 pid=4085 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="arpwatch" exe="/usr/sbin/arpwatch" subj=unconfined_u:system_r:arpwatch_t:s0 key=(null)
> type=SYSCALL msg=audit(1259008591.317:107845): arch=c000003e syscall=54
> success=yes exit=0 a0=0 a1=107 a2=1 a3=7fff01307560 items=0 ppid=1
> pid=4085 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0
> fsgid=0 tty=(none) ses=1 comm="arpwatch" exe="/usr/sbin/arpwatch"
> subj=unconfined_u:system_r:arpwatch_t:s0 key=(null)
> 
> Cheers, Paul.
> 
> --
> fedora-selinux-list mailing list
> fedora-selinux-list at redhat.com
> https://www.redhat.com/mailman/listinfo/fedora-selinux-list
> 
> 
Sorry you missed this weeks boat, Just released 49 to updates testing.  Fixed in -50.




More information about the fedora-selinux-list mailing list