[Arm-dev] SELinux warnings?

Robert Moskowitz rgm at htt-consult.com
Thu Oct 18 20:14:10 UTC 2018


I am assuming that none of these are a problem, other than they occur 
anytime you do anything with SELinux, like get an update:

   Updating   : 
selinux-policy-targeted-3.13.1-192.el7_5.6.noarch         52/163
[  864.238915] SELinux:  Permission getrlimit in class process not 
defined in policy.
[  864.255572] SELinux:  Permission map in class file not defined in policy.
[  864.271347] SELinux:  Permission map in class dir not defined in policy.
[  864.287009] SELinux:  Permission map in class lnk_file not defined in 
policy.
[  864.302952] SELinux:  Permission map in class chr_file not defined in 
policy.
[  864.318679] SELinux:  Permission map in class blk_file not defined in 
policy.
[  864.334072] SELinux:  Permission map in class sock_file not defined 
in policy.
[  864.349585] SELinux:  Permission map in class fifo_file not defined 
in policy.
[  864.364986] SELinux:  Permission map in class socket not defined in 
policy.
[  864.380106] SELinux:  Permission map in class tcp_socket not defined 
in policy.
[  864.395447] SELinux:  Permission map in class udp_socket not defined 
in policy.
[  864.410657] SELinux:  Permission map in class rawip_socket not 
defined in policy.
[  864.425984] SELinux:  Permission map in class netlink_socket not 
defined in policy.
[  864.441531] SELinux:  Permission map in class packet_socket not 
defined in policy.
[  864.457032] SELinux:  Permission map in class key_socket not defined 
in policy.
[  864.472253] SELinux:  Permission map in class unix_stream_socket not 
defined in policy.
[  864.488097] SELinux:  Permission map in class unix_dgram_socket not 
defined in policy.
[  864.503933] SELinux:  Permission map in class netlink_route_socket 
not defined in policy.
[  864.519918] SELinux:  Permission map in class netlink_tcpdiag_socket 
not defined in policy.
[  864.536181] SELinux:  Permission map in class netlink_nflog_socket 
not defined in policy.
[  864.552161] SELinux:  Permission map in class netlink_xfrm_socket not 
defined in policy.
[  864.568076] SELinux:  Permission map in class netlink_selinux_socket 
not defined in policy.
[  864.584204] SELinux:  Permission map in class netlink_iscsi_socket 
not defined in policy.
[  864.600178] SELinux:  Permission map in class netlink_audit_socket 
not defined in policy.
[  864.616037] SELinux:  Permission map in class 
netlink_fib_lookup_socket not defined in policy.
[  864.632237] SELinux:  Permission map in class 
netlink_connector_socket not defined in policy.
[  864.648096] SELinux:  Permission map in class 
netlink_netfilter_socket not defined in policy.
[  864.663754] SELinux:  Permission map in class netlink_dnrt_socket not 
defined in policy.
[  864.678752] SELinux:  Permission map in class 
netlink_kobject_uevent_socket not defined in policy.
[  864.694514] SELinux:  Permission map in class netlink_generic_socket 
not defined in policy.
[  864.709433] SELinux:  Permission map in class 
netlink_scsitransport_socket not defined in policy.
[  864.724784] SELinux:  Permission map in class netlink_rdma_socket not 
defined in policy.
[  864.739110] SELinux:  Permission map in class netlink_crypto_socket 
not defined in policy.
[  864.753607] SELinux:  Permission map in class appletalk_socket not 
defined in policy.
[  864.767591] SELinux:  Permission map in class dccp_socket not defined 
in policy.
[  864.781189] SELinux:  Permission map in class tun_socket not defined 
in policy.
[  864.794607] SELinux:  Class sctp_socket not defined in policy.
[  864.806570] SELinux:  Class icmp_socket not defined in policy.
[  864.818225] SELinux:  Class ax25_socket not defined in policy.
[  864.829649] SELinux:  Class ipx_socket not defined in policy.
[  864.840752] SELinux:  Class netrom_socket not defined in policy.
[  864.851923] SELinux:  Class atmpvc_socket not defined in policy.
[  864.862911] SELinux:  Class x25_socket not defined in policy.
[  864.873393] SELinux:  Class rose_socket not defined in policy.
[  864.883767] SELinux:  Class decnet_socket not defined in policy.
[  864.894133] SELinux:  Class atmsvc_socket not defined in policy.
[  864.904385] SELinux:  Class rds_socket not defined in policy.
[  864.914444] SELinux:  Class irda_socket not defined in policy.
[  864.924608] SELinux:  Class pppox_socket not defined in policy.
[  864.934862] SELinux:  Class llc_socket not defined in policy.
[  864.944876] SELinux:  Class can_socket not defined in policy.
[  864.954877] SELinux:  Class tipc_socket not defined in policy.
[  864.964974] SELinux:  Class bluetooth_socket not defined in policy.
[  864.975659] SELinux:  Class iucv_socket not defined in policy.
[  864.985843] SELinux:  Class rxrpc_socket not defined in policy.
[  864.996237] SELinux:  Class isdn_socket not defined in policy.
[  865.006492] SELinux:  Class phonet_socket not defined in policy.
[  865.017007] SELinux:  Class ieee802154_socket not defined in policy.
[  865.027974] SELinux:  Class caif_socket not defined in policy.
[  865.038332] SELinux:  Class alg_socket not defined in policy.
[  865.048641] SELinux:  Class nfc_socket not defined in policy.
[  865.058824] SELinux:  Class vsock_socket not defined in policy.
[  865.069225] SELinux:  Class kcm_socket not defined in policy.
[  865.079405] SELinux:  Class qipcrtr_socket not defined in policy.
[  865.090009] SELinux:  Class smc_socket not defined in policy.
[  865.100225] SELinux: the above unknown classes and permissions will 
be allowed
[  870.760142] SELinux:  Context 
unconfined_u:unconfined_r:sandbox_t:s0-s0:c0.c1023 became invalid 
(unmapped).
[  871.187593] SELinux:  Context 
system_u:unconfined_r:sandbox_t:s0-s0:c0.c1023 became invalid (unmapped).
[  872.635092] SELinux:  policy capability network_peer_controls=1
[  872.645801] SELinux:  policy capability open_perms=1
[  872.655404] SELinux:  policy capability extended_socket_class=0
[  872.666023] SELinux:  policy capability always_check_network=0
[  872.676507] SELinux:  policy capability cgroup_seclabel=1
[  872.686511] SELinux:  policy capability nnp_nosuid_transition=1


that is quite an extensive list...




More information about the Arm-dev mailing list