概述:
SELinux is preventing consoletype (consoletype_t) "read" to
/var/lib/dhclient/dhclient-wlan0.leases (dhcpc_state_t).
详细描述:
SELinux denied access requested by consoletype. It is not expected that this
access is required by consoletype and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of the
application is causing it to require additional access.
允许访问:
Sometimes labeling problems can cause SELinux denials. You could try to restore
the default system file context for /var/lib/dhclient/dhclient-wlan0.leases,
restorecon -v '/var/lib/dhclient/dhclient-wlan0.leases'
If this does not work, there is currently no automatic way to allow this access.
Instead, you can generate a local policy module to allow this access - see FAQ
(
http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable
SELinux protection altogether. Disabling SELinux protection is not recommended.
Please file a bug report (
http://bugzilla.redhat.com/bugzilla/enter_bug.cgi)
against this package.
附加信息:
源上下文 unconfined_u:system_r:consoletype_t:s0
目标上下文 unconfined_ubject_r:dhcpc_state_t:s0

目标对象 /var/lib/dhclient/dhclient-wlan0.leases [ file ]
源 consoletype
源路径 /sbin/consoletype
端口 <未知>
主机 localhost.localdomain
源 RPM 软件包 initscripts-8.86-1
目标 RPM 软件包
策略 RPM selinux-policy-3.5.13-18.fc10
启用 Selinux True
策略类型 targeted
启用 MLS True
Enforcing 模式 Enforcing
插件名称 catchall_file
主机名 localhost.localdomain
平台 Linux localhost.localdomain 2.6.27.5-117.fc10.i686
#1 SMP Tue Nov 18 12:19:59 EST 2008 i686 i686
警报计数 1
第一个 2008年12月13日 星期六 22时46分55秒
最后一个 2008年12月13日 星期六 23时07分36秒
本地 ID 040a8d99-d7a6-41f5-b4c7-fbbe44ff099e
行号
原始核查信息
node=localhost.localdomain type=AVC msg=audit(1229180856.788:49): avc: denied { read } for pid=4832 comm="consoletype" path="/var/lib/dhclient/dhclient-wlan0.leases" dev=dm-0 ino=245925 scontext=unconfined_u:system_r:consoletype_t:s0 tcontext=unconfined_ubject_r:dhcpc_state_t:s0 tclass=file

node=localhost.localdomain type=SYSCALL msg=audit(1229180856.788:49): arch=40000003 syscall=11 success=yes exit=0 a0=9353248 a1=93565b8 a2=9352fd0 a3=0 items=0 ppid=4831 pid=4832 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=2 comm="consoletype" exe="/sbin/consoletype" subj=unconfined_u:system_r:consoletype_t:s0 key=(null)