Why I am getting SELinux denials when rotating audit logs using logrotate ?
Issue
- Why I am getting
selinuxdenials when rotating audit logs usinglogrotate? - The
AVC'sare:
type=AVC msg=audit(1405669322.312:340285): avc: denied { ioctl } for pid=12526 comm="gzip" path="/var/log/audit/audit.log-20140718.gz" dev=dm-5 ino=264102 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s0 tclass=file
type=AVC msg=audit(1405669322.861:340286): avc: denied { unlink } for pid=12493 comm="logrotate" name="audit.log-20140718" dev=dm-5 ino=264074 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s0 tclass=file
type=AVC msg=audit(1404198541.541:1193914): avc: denied { getattr } for pid=12549 comm="logrotate" path="/var/log/audit/audit.log" dev=dm-5 ino=262678 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:auditd_log_t:s0 tclass=file
Environment
- Red Hat Enterprise Linux (All Versions)
- selinux-policy
- audit
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.