Selinux m'indique toujours les même problèmes à chaque démarrage, et je ne sais pas s'il est judicieux d'autoriser les service bloqué :
Services bloqués :
udev-113-12.fc7 [application] (x6)
cups-1.2.12-4.fc7 [application] (x29)
dhclient-3.0.5-40.fc7 [application] (31)
system_u:system_r:cupsd_config_t (x12)
system_u:system_r:hplip_t (x1)
util-linux-2.13-0.54.fc7 [application] (x1)
Pour plus de détails, les messages explicatifs des blocages :
dev-113-12.fc7 [application] (x6)
Summary
SELinux is preventing /sbin/udevd (udev_t) "relabelfrom" to par0 (device_t).
Detailed Description
SELinux denied access requested by /sbin/udevd. It is not expected that this
access is required by /sbin/udevd and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of
the application is causing it to require additional access.
Allowing Access
Sometimes labeling problems can cause SELinux denials. You could try to
restore the default system file context for par0, restorecon -v par0 If this
does not work, there is currently no automatic way to allow this access.
Instead, you can generate a local policy module to allow this access - see
http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385 Or you can disable
SELinux protection altogether. Disabling SELinux protection is not
recommended. Please file a http://bugzilla.redhat.com/bugzilla/enter_bug.cgi
against this package.
Additional Information
Source Context system_u:system_r:udev_t:SystemLow-SystemHigh
Target Context system_u:object_r:device_t
Target Objects par0 [ lnk_file ]
Affected RPM Packages udev-113-12.fc7 [application]
Policy RPM selinux-policy-2.6.4-43.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.catchall_file
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.9-91.fc7 #1 SMP
Thu Sep 27 23:10:59 EDT 2007 i686 athlon
Alert Count 6
First Seen mer 19 sep 2007 12:09:03 CEST
Last Seen mer 03 oct 2007 08:04:45 CEST
Local ID e0957884-28a3-4256-8ab6-bc873aec0951
Line Numbers
Raw Audit Messages
avc: denied { relabelfrom } for comm="udevd" dev=tmpfs egid=0 euid=0
exe="/sbin/udevd" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="par0" pid=3077
scontext=system_u:system_r:udev_t:s0-s0:c0.c1023 sgid=0
subj=system_u:system_r:udev_t:s0-s0:c0.c1023 suid=0 tclass=lnk_file
tcontext=system_u:object_r:device_t:s0 tty=(none) uid=0
cups-1.2.12-4.fc7 [application] (x29)
Summary
SELinux is preventing the /usr/sbin/cupsd from using potentially mislabeled
files (services).
Detailed Description
SELinux has denied /usr/sbin/cupsd access to potentially mislabeled file(s)
(services). This means that SELinux will not allow /usr/sbin/cupsd to use
these files. It is common for users to edit files in their home directory
or tmp directories and then move (mv) them to system directories. The
problem is that the files end up with the wrong file context which confined
applications are not allowed to access.
Allowing Access
If you want /usr/sbin/cupsd to access this files, you need to relabel them
using restorecon -v services. You might want to relabel the entire
directory using restorecon -R -v .
Additional Information
Source Context system_u:system_r:cupsd_t:SystemLow-SystemHigh
Target Context system_u:object_r:rpm_script_tmp_t
Target Objects services [ file ]
Affected RPM Packages cups-1.2.12-4.fc7 [application]
Policy RPM selinux-policy-2.6.4-43.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.home_tmp_bad_labels
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.9-91.fc7 #1 SMP
Thu Sep 27 23:10:59 EDT 2007 i686 athlon
Alert Count 29
First Seen jeu 20 sep 2007 08:49:27 CEST
Last Seen mer 03 oct 2007 07:33:47 CEST
Local ID 7ad675bb-079a-498c-85e5-8a305b12b065
Line Numbers
Raw Audit Messages
avc: denied { read } for comm="cupsd" dev=sda9 egid=0 euid=0
exe="/usr/sbin/cupsd" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="services"
pid=2103 scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 sgid=0
subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 suid=0 tclass=file
tcontext=system_u:object_r:rpm_script_tmp_t:s0 tty=(none) uid=0
dhclient-3.0.5-40.fc7 [application] (31)
Summary
SELinux is preventing the /sbin/dhclient from using potentially mislabeled
files (services).
Detailed Description
SELinux has denied /sbin/dhclient access to potentially mislabeled file(s)
(services). This means that SELinux will not allow /sbin/dhclient to use
these files. It is common for users to edit files in their home directory
or tmp directories and then move (mv) them to system directories. The
problem is that the files end up with the wrong file context which confined
applications are not allowed to access.
Allowing Access
If you want /sbin/dhclient to access this files, you need to relabel them
using restorecon -v services. You might want to relabel the entire
directory using restorecon -R -v .
Additional Information
Source Context system_u:system_r:dhcpc_t
Target Context system_u:object_r:rpm_script_tmp_t
Target Objects services [ file ]
Affected RPM Packages dhclient-3.0.5-40.fc7 [application]
Policy RPM selinux-policy-2.6.4-43.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.home_tmp_bad_labels
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.9-91.fc7 #1 SMP
Thu Sep 27 23:10:59 EDT 2007 i686 athlon
Alert Count 31
First Seen jeu 20 sep 2007 08:49:37 CEST
Last Seen mer 03 oct 2007 07:33:58 CEST
Local ID 6b1b446d-ce1a-443c-8cdd-bc6ede76fd26
Line Numbers
Raw Audit Messages
avc: denied { read } for comm="dhclient" dev=sda9 egid=0 euid=0
exe="/sbin/dhclient" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="services"
pid=2566 scontext=system_u:system_r:dhcpc_t:s0 sgid=0
subj=system_u:system_r:dhcpc_t:s0 suid=0 tclass=file
tcontext=system_u:object_r:rpm_script_tmp_t:s0 tty=(none) uid=0
system_u:system_r:cupsd_config_t (x12)
Summary
SELinux is preventing the python from using potentially mislabeled files
(services).
Detailed Description
SELinux has denied python access to potentially mislabeled file(s)
(services). This means that SELinux will not allow python to use these
files. It is common for users to edit files in their home directory or tmp
directories and then move (mv) them to system directories. The problem is
that the files end up with the wrong file context which confined
applications are not allowed to access.
Allowing Access
If you want python to access this files, you need to relabel them using
restorecon -v services. You might want to relabel the entire directory
using restorecon -R -v .
Additional Information
Source Context system_u:system_r:cupsd_config_t
Target Context system_u:object_r:rpm_script_tmp_t
Target Objects services [ file ]
Affected RPM Packages
Policy RPM selinux-policy-2.6.4-43.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.home_tmp_bad_labels
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.9-91.fc7 #1 SMP
Thu Sep 27 23:10:59 EDT 2007 i686 athlon
Alert Count 12
First Seen sam 22 sep 2007 11:06:44 CEST
Last Seen mer 03 oct 2007 08:04:45 CEST
Local ID b35d2403-d2d5-4b94-96b5-98cc4fee1ab7
Line Numbers
Raw Audit Messages
avc: denied { read } for comm="python" dev=sda9 egid=0 euid=0
exe="/usr/bin/python" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="services"
pid=3083 scontext=system_u:system_r:cupsd_config_t:s0 sgid=0
subj=system_u:system_r:cupsd_config_t:s0 suid=0 tclass=file
tcontext=system_u:object_r:rpm_script_tmp_t:s0 tty=(none) uid=0
system_u:system_r:hplip_t (x1)
Summary
SELinux is preventing the python from using potentially mislabeled files
(services).
Detailed Description
SELinux has denied python access to potentially mislabeled file(s)
(services). This means that SELinux will not allow python to use these
files. It is common for users to edit files in their home directory or tmp
directories and then move (mv) them to system directories. The problem is
that the files end up with the wrong file context which confined
applications are not allowed to access.
Allowing Access
If you want python to access this files, you need to relabel them using
restorecon -v services. You might want to relabel the entire directory
using restorecon -R -v .
Additional Information
Source Context system_u:system_r:hplip_t
Target Context system_u:object_r:rpm_script_tmp_t
Target Objects services [ file ]
Affected RPM Packages
Policy RPM selinux-policy-2.6.4-43.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.home_tmp_bad_labels
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.9-91.fc7 #1 SMP
Thu Sep 27 23:10:59 EDT 2007 i686 athlon
Alert Count 1
First Seen sam 22 sep 2007 11:06:57 CEST
Last Seen mer 03 oct 2007 08:04:44 CEST
Local ID c79c6177-5e27-4df6-b301-f291191ab43a
Line Numbers
Raw Audit Messages
avc: denied { read } for comm="python" dev=sda9 egid=0 euid=0
exe="/usr/bin/python" exit=-13 fsgid=0 fsuid=0 gid=0 items=0 name="services"
pid=2091 scontext=system_u:system_r:hplip_t:s0 sgid=0
subj=system_u:system_r:hplip_t:s0 suid=0 tclass=file
tcontext=system_u:object_r:rpm_script_tmp_t:s0 tty=(none) uid=0
util-linux-2.13-0.54.fc7 [application] (x1)
Summary
SELinux prevented /bin/mount from mounting on the file or directory
"<Unknown>" (type "unlabeled_t").
Detailed Description
SELinux prevented /bin/mount from mounting a filesystem on the file or
directory "<Unknown>" of type "unlabeled_t". By default SELinux limits the
mounting of filesystems to only some files or directories (those with types
that have the mountpoint attribute). The type "unlabeled_t" does not have
this attribute. You can either relabel the file or directory or set the
boolean "allow_mount_anyfile" to true to allow mounting on any file or
directory.
Allowing Access
Changing the "allow_mount_anyfile" boolean to true will allow this access:
"setsebool -P allow_mount_anyfile=1."
The following command will allow this access:
setsebool -P allow_mount_anyfile=1
Additional Information
Source Context system_u:system_r:mount_t
Target Context system_u:object_r:unlabeled_t
Target Objects None [ file ]
Affected RPM Packages util-linux-2.13-0.54.fc7 [application]
Policy RPM selinux-policy-2.6.4-42.fc7
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name plugins.allow_mount_anyfile
Host Name localhost.localdomain
Platform Linux localhost.localdomain 2.6.22.5-76.fc7 #1 SMP
Thu Aug 30 13:47:21 EDT 2007 i686 athlon
Alert Count 1
First Seen mer 26 sep 2007 23:38:20 CEST
Last Seen mer 26 sep 2007 23:38:20 CEST
Local ID 0b8814c9-4776-46bd-91e4-c866301e2733
Line Numbers
Raw Audit Messages
avc: denied { write } for comm="mount" dev=bdev egid=0 euid=0 exe="/bin/mount"
exit=-22 fsgid=0 fsuid=0 gid=0 items=0 pid=2963
scontext=system_u:system_r:mount_t:s0 sgid=0 subj=system_u:system_r:mount_t:s0
suid=0 tclass=file tcontext=system_u:object_r:unlabeled_t:s0 tty=(none) uid=0