bizarre packet labelings

brian retford bretford at gmail.com
Wed Jun 17 17:18:23 UTC 2009


We have a fairly customized centos 5.3 distribution, but I know of nothing
that would cause the behavior I'm seeing. We don't use iptables or ipsec,
secmark is enabled in the kernel. I get avc denied messages for packets that
almost certainly do exist, but the targets almost never make sense (at least
to me), things like ls_exec_t, lib_t, and other seemingly random types.
Thoughts?

avc:  denied  { send } for  pid=3202 comm="sshd" saddr=172.27.13.41 src=22
daddr=172.27.134.1 dest=40428 netif=eth0
scontext=system_u:system_r:unconfined_t:s0-s0:c0.c1023
tcontext=system_u:object_r:lib_t:s0 tclass=packet

-b
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/fedora-selinux-list/attachments/20090617/df9bc512/attachment.htm>


More information about the fedora-selinux-list mailing list