Re: Fedora 32 and SELinux : syntax errors for mlsconstrain

Cătălin George Feștilă <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
my user is set to staff_u

[root@desk mythcat]# ausearch -m AVC -ts recent
----
time->Mon Sep 21 23:12:51 2020
type=AVC msg=audit(1600719171.505:604): avc:  denied  { watch } for  pid=1 comm="systemd" path="/sys/fs/cgroup/system.slice/fprintd.service/cgroup.events" dev="cgroup2" ino=6534 scontext=system_u:system_r:init_t:s0-s15:c0.c1023 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=1
----
time->Mon Sep 21 23:13:31 2020
type=AVC msg=audit(1600719211.995:628): avc:  denied  { search } for  pid=7838 comm="ausearch" name="audit" dev="dm-0" ino=25498338 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_etc_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:13:31 2020
type=AVC msg=audit(1600719211.995:629): avc:  denied  { read } for  pid=7838 comm="ausearch" name="auditd.conf" dev="dm-0" ino=25498340 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_etc_t:s15:c0.c1023 tclass=file permissive=1
----
time->Mon Sep 21 23:13:32 2020
type=AVC msg=audit(1600719212.142:630): avc:  denied  { read } for  pid=7838 comm="ausearch" name="audit" dev="dm-0" ino=8489316 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:13:32 2020
type=AVC msg=audit(1600719212.142:631): avc:  denied  { search } for  pid=7838 comm="ausearch" name="audit" dev="dm-0" ino=8489316 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:13:32 2020
type=AVC msg=audit(1600719212.142:632): avc:  denied  { read } for  pid=7838 comm="ausearch" name="audit.log" dev="dm-0" ino=8606022 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=file permissive=1
----
time->Mon Sep 21 23:13:37 2020
type=AVC msg=audit(1600719217.510:633): avc:  denied  { getattr } for  pid=5995 comm="setroubleshootd" path="/etc/audit" dev="dm-0" ino=25498338 scontext=system_u:system_r:setroubleshootd_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_etc_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:13:39 2020
type=AVC msg=audit(1600719219.384:634): avc:  denied  { watch } for  pid=1 comm="systemd" path="/sys/fs/cgroup/system.slice/system-dbus\x2d:1.10\x2dorg.fedoraproject.SetroubleshootPrivileged.slice/dbus-:[email protected]/cgroup.events" dev="cgroup2" ino=6565 scontext=system_u:system_r:init_t:s0-s15:c0.c1023 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=1
----
time->Mon Sep 21 23:13:40 2020
type=AVC msg=audit(1600719220.212:636): avc:  denied  { getattr } for  pid=5995 comm="setroubleshootd" path="/var/log/audit" dev="dm-0" ino=8489316 scontext=system_u:system_r:setroubleshootd_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:17:37 2020
type=AVC msg=audit(1600719457.649:646): avc:  denied  { search } for  pid=8097 comm="ausearch" name="audit" dev="dm-0" ino=25498338 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_etc_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:17:37 2020
type=AVC msg=audit(1600719457.649:647): avc:  denied  { read } for  pid=8097 comm="ausearch" name="auditd.conf" dev="dm-0" ino=25498340 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_etc_t:s15:c0.c1023 tclass=file permissive=1
----
time->Mon Sep 21 23:17:37 2020
type=AVC msg=audit(1600719457.650:648): avc:  denied  { read } for  pid=8097 comm="ausearch" name="audit" dev="dm-0" ino=8489316 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:17:37 2020
type=AVC msg=audit(1600719457.650:649): avc:  denied  { search } for  pid=8097 comm="ausearch" name="audit" dev="dm-0" ino=8489316 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=dir permissive=1
----
time->Mon Sep 21 23:17:37 2020
type=AVC msg=audit(1600719457.650:650): avc:  denied  { read } for  pid=8097 comm="ausearch" name="audit.log" dev="dm-0" ino=8606022 scontext=staff_u:staff_r:staff_t:s0-s15:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s15:c0.c1023 tclass=file permissive=1
[root@desk mythcat]# ausearch -m AVC -ts recent | audit2allow -R
libsepol.sepol_string_to_av_perm: could not convert watch to av bit
libsepol.sepol_string_to_av_perm: could not convert watch to av bit
libsepol.sepol_string_to_av_perm: could not convert watch to av bit
could not open interface info [/var/lib/sepolgen/interface_info]
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.