View Issue Details

IDProjectCategoryView StatusLast Update
0015719CentOS-7selinux-policypublic2019-01-17 23:37
ReporterMbonilla94 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
PlatformOSOS Version7
Product Version 
Target VersionFixed in Version 
Summary0015719: SELinux is preventing /usr/sbin/zabbix_server_mysql from 'create' accesses on the sock_file /var/run/zabbix/zabbix_server_pre...
DescriptionDescription of problem:
SELinux is preventing /usr/sbin/zabbix_server_mysql from 'create' accesses on the sock_file /var/run/zabbix/zabbix_server_preprocessing.sock.

***** Plugin catchall (100. confidence) suggests **************************

Si cree que de manera predeterminada se debería permitir a zabbix_server_mysql el acceso create sobre zabbix_server_preprocessing.sock sock_file.
Then debería reportar esto como un error.
Puede generar un módulo de política local para permitir este acceso.
Do
permita el acceso temporalmente ejecutando:
# ausearch -c 'zabbix_server' --raw | audit2allow -M mi-zabbixserver
# semodule -i mi-zabbixserver.pp

Additional Information:
Source Context system_u:system_r:zabbix_t:s0
Target Context system_u:object_r:zabbix_var_run_t:s0
Target Objects /var/run/zabbix/zabbix_server_preprocessing.sock [
                              sock_file ]
Source zabbix_server
Source Path /usr/sbin/zabbix_server_mysql
Port <Unknown>
Host (removed)
Source RPM Packages zabbix-server-mysql-4.0.3-1.el7.x86_64
Target RPM Packages
Policy RPM selinux-policy-3.13.1-192.el7.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name (removed)
Platform Linux (removed) 3.10.0-862.el7.x86_64 #1 SMP Fri
                              Apr 20 16:44:24 UTC 2018 x86_64 x86_64
Alert Count 42
First Seen 2019-01-17 17:24:18 CST
Last Seen 2019-01-17 17:29:07 CST
Local ID 8e4033fd-ae69-4db2-8ede-e3c00b466953

Raw Audit Messages
type=AVC msg=audit(1547767747.692:4299): avc: denied { create } for pid=61278 comm="zabbix_server" name="zabbix_server_preprocessing.sock" scontext=system_u:system_r:zabbix_t:s0 tcontext=system_u:object_r:zabbix_var_run_t:s0 tclass=sock_file


type=SYSCALL msg=audit(1547767747.692:4299): arch=x86_64 syscall=bind success=no exit=EACCES a0=7 a1=7fff3e7f3210 a2=6e a3=fffffe00 items=2 ppid=61232 pid=61278 auid=4294967295 uid=988 gid=982 euid=988 suid=988 fsuid=988 egid=982 sgid=982 fsgid=982 tty=(none) ses=4294967295 comm=zabbix_server exe=/usr/sbin/zabbix_server_mysql subj=system_u:system_r:zabbix_t:s0 key=(null)

type=CWD msg=audit(1547767747.692:4299): cwd=/

type=PATH msg=audit(1547767747.692:4299): item=0 name=/var/run/zabbix/ inode=47464 dev=00:13 mode=040755 ouid=988 ogid=982 rdev=00:00 obj=system_u:object_r:zabbix_var_run_t:s0 objtype=PARENT cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0

type=PATH msg=audit(1547767747.692:4299): item=1 name=/var/run/zabbix/zabbix_server_preprocessing.sock objtype=CREATE cap_fp=0000000000000000 cap_fi=0000000000000000 cap_fe=0 cap_fver=0

Hash: zabbix_server,zabbix_t,zabbix_var_run_t,sock_file,create

Version-Release number of selected component:
selinux-policy-3.13.1-192.el7.noarch
Additional Informationreporter: libreport-2.1.11.1
hashmarkername: setroubleshoot
kernel: 3.10.0-862.el7.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.
abrt_hash8a95f0ce048925f7198f9f5cd046e0e48fe1c07116bfc5e7cd4101ba0347b6b7
URL

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2019-01-17 23:37 Mbonilla94 New Issue