Re: selinux vbetool error

2011-03-10 Thread Alex
>> # cat mylog >> type=AVC msg=audit(1299774763.043:2272): avc:  denied  { getattr } for >>  pid=3245 comm="httpd" path="/etc/munin/htpasswd.users" dev=sda1 >> ino=3543833 scontext=system_u:system_r:httpd_t:s0 >> tcontext=system_u:object_r:munin_etc_t:s0 tclass=file >> type=AVC msg=audit(1299777304

Re: selinux vbetool error

2011-03-10 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/10/2011 12:18 PM, Alex wrote: > Hi, > >>> is this a problem with the policy for munin or my system in general? >> >> If you have already relabeled (and it sounds like you have) then yes, it >> would be a bug with selinux-policy. >> >> You can al

Re: selinux vbetool error

2011-03-10 Thread Alex
Hi, >> is this a problem with the policy for munin or my system in general? > > If you have already relabeled (and it sounds like you have) then yes, it > would be a bug with selinux-policy. > > You can always generate a policy to workaround the issue with: > > $ audit2allow -M mypolicy > [paste A

Re: selinux vbetool error

2011-03-10 Thread Michael Cronenworth
Alex wrote: > is this a problem with the policy for munin or my system in general? If you have already relabeled (and it sounds like you have) then yes, it would be a bug with selinux-policy. You can always generate a policy to workaround the issue with: $ audit2allow -M mypolicy [paste AVC mes

Re: selinux vbetool error

2011-03-10 Thread Alex
Hi, >> I've tried running this through audit2allow but it doesn't seem to >> resolve it, even after rebooting and relabeling. >> >> # egrep "httpd|perl|munin|crond" /var/log/audit/audit.log | audit2allow -M >> mypol >> # semodule -i mypol.pp >> >> These are all related to my recent install of mun

Re: selinux vbetool error

2011-03-10 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/09/2011 06:25 PM, Alex wrote: > Hi, > > As a follow-up to my own post, I now have several other selinux errors > that I can't figure out: > > type=SYSCALL msg=audit(1299712804.077:53): arch=c03e syscall=2 > success=no exit=-13 a0=fac5b0 a1=

Re: selinux vbetool error

2011-03-09 Thread stan
On Wed, 9 Mar 2011 16:53:48 -0500 Alex wrote: > eventually completing the upgrade, I'm left with one remaining selinux > error that I can't figure out: > > [ 10.017350] type=1400 audit(1299697430.359:4): avc: denied { > mmap_zero } for pid=664 comm="vbetool" > scontext=system_u:system_r:vbe

Re: selinux vbetool error

2011-03-09 Thread Alex
Hi, As a follow-up to my own post, I now have several other selinux errors that I can't figure out: type=SYSCALL msg=audit(1299712804.077:53): arch=c03e syscall=2 success=no exit=-13 a0=fac5b0 a1=241 a2=1b6 a3=3293127420 items=0 ppid=3264 pid=3447 auid=4294967295 uid=489 gid=485 euid=489 suid

Re: selinux vbetool error

2011-03-09 Thread Alex
Hi, >> [   10.017350] type=1400 audit(1299697430.359:4): avc:  denied  { >> mmap_zero } for  pid=664 comm="vbetool" >> scontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 >> tcontext=system_u:system_r:vbetool_t:s0-s0:c0.c1023 tclass=memprotect >> >> What is the cause of this, and any suggestions o

Re: selinux vbetool error

2011-03-09 Thread Daniel J Walsh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/09/2011 04:53 PM, Alex wrote: > Hi all, > > I've just upgraded an fc13 x86_64 box to fc14, and had quite a bit of > trouble with the upgrade process due to a hardware problem. After > eventually completing the upgrade, I'm left with one remainin

selinux vbetool error

2011-03-09 Thread Alex
Hi all, I've just upgraded an fc13 x86_64 box to fc14, and had quite a bit of trouble with the upgrade process due to a hardware problem. After eventually completing the upgrade, I'm left with one remaining selinux error that I can't figure out: [ 10.017350] type=1400 audit(1299697430.359:4): a