2017-09-21 12:23 UTC

View Issue Details Jump to Notes ]
IDProjectCategoryView StatusLast Update
0013550CentOS-7selinux-policypublic2017-07-14 12:49
Reporterbarywhyte 
PrioritynormalSeverityminorReproducibilityhave not tried
StatusnewResolutionopen 
PlatformOSOS Version7
Product Version 
Target VersionFixed in Version 
Summary0013550: SELinux is preventing /usr/bin/bash from 'write' accesses on the directory ksm.
DescriptionDescription of problem:
I tried to restart icinga
# sudo systemctl restart icinga
SELinux is preventing /usr/bin/bash from 'write' accesses on the directory ksm.

***** Plugin catchall (100. confidence) suggests **************************

If you believe that bash should be allowed write access on the ksm directory by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'ksmtuned' --raw | audit2allow -M my-ksmtuned
# semodule -i my-ksmtuned.pp

Additional Information:
Source Context system_u:system_r:ksmtuned_t:s0
Target Context system_u:object_r:sysfs_t:s0
Target Objects ksm [ dir ]
Source ksmtuned
Source Path /usr/bin/bash
Port <Unknown>
Host (removed)
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.13.1-102.el7_3.16.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name (removed)
Platform Linux (removed) 4.11.7-1.el7.elrepo.x86_64 #1 SMP
                              Sat Jun 24 09:49:01 EDT 2017 x86_64 x86_64
Alert Count 168
First Seen 2017-07-11 08:40:45 WAT
Last Seen 2017-07-14 13:37:38 WAT
Local ID 970099f8-e4a6-483b-938a-c6fe638db7f8

Raw Audit Messages
type=AVC msg=audit(1500035858.506:398): avc: denied { write } for pid=842 comm="ksmtuned" name="ksm" dev="sysfs" ino=1432 scontext=system_u:system_r:ksmtuned_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=dir permissive=0


Hash: ksmtuned,ksmtuned_t,sysfs_t,dir,write

Version-Release number of selected component:
selinux-policy-3.13.1-102.el7_3.16.noarch
Additional Informationreporter: libreport-2.1.11.1
hashmarkername: setroubleshoot
kernel: 4.11.7-1.el7.elrepo.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.
abrt_hash260f4ec05ad8e364ade139acc825b11673113cfc5d9c1046e9e6efd3beb53a8f
URL
Attached Files

-Relationships
+Relationships

-Notes
There are no notes attached to this issue.
+Notes

-Issue History
Date Modified Username Field Change
2017-07-14 12:49 barywhyte New Issue
+Issue History