Wind River Support Network

Fixed

OVP-7 : ifconfig gets SELinux AVC denials for sys_nice and setsched

Created: Sep 27, 2013    Updated: Mar 11, 2016
Resolved Date: Nov 3, 2013
Found In Version: 5.0.1
Fix Version: 5.0.1.9
Severity: Severe
Applicable for: Wind River Linux 5
Component/s: Userspace

Description

I'm seeing the following in /var/log/messages (which means that it happens before auditd starts):

  2013-09-27T13:23:57.907595-06:00 donn-gandy kernel: type=1400 audit(1380309829.200:3): avc:  denied  { sys_nice } for  pid=1228 comm="ifconfig" capability=23  scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:system_r:ifconfig_t:s0 tclass=capability
  2013-09-27T13:23:57.907596-06:00 donn-gandy kernel: type=1400 audit(1380309829.203:4): avc:  denied  { setsched } for  pid=1228 comm="ifconfig" scontext=system_u:system_r:ifconfig_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=process

Steps to Reproduce

Build and boot an OVP node.
Check /var/log/messages.
Live chat
Online