<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-24816</id>
	<title>Nabble - Fedora SELinux List</title>
	<updated>2009-12-16T07:00:23Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Fedora-SELinux-List-f24816.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-SELinux-List-f24816.html" />
	<subtitle type="html">For discussions about the Fedora SELinux Project.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26812436</id>
	<title>RE: how to restrict a SOCK_RAW by interface</title>
	<published>2009-12-16T07:00:23Z</published>
	<updated>2009-12-16T07:00:23Z</updated>
	<author>
		<name>Stephen Smalley</name>
	</author>
	<content type="html">On Mon, 2009-12-14 at 16:56 -0600, Cernak, James E (IS) wrote:
&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks for the hint, However it does not solve my problem I still can
&lt;br&gt;&amp;gt; read from eth0.
&lt;br&gt;&lt;br&gt;eth0 or eth1? &amp;nbsp;Your example showed eth1 configured as iface_test_t.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I did have to add allow rules for netif_t:netif but my policy still
&lt;br&gt;&amp;gt; does not allow iface_test_t.
&lt;br&gt;&lt;br&gt;Hmmm..are you sure? &amp;nbsp;Did you declare any type attributes for
&lt;br&gt;iface_test_t? &amp;nbsp;Use sesearch or apol to confirm that there are no allow
&lt;br&gt;rules to it in the final binary policy.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; James
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: Stephen Smalley [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26812436&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sds@...&lt;/a&gt;]
&lt;br&gt;&amp;gt; Sent: Mon 12/14/2009 1:49 PM
&lt;br&gt;&amp;gt; To: Cernak, James E (IS)
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26812436&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: how to restrict a SOCK_RAW by interface
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Mon, 2009-12-14 at 13:29 -0600, Cernak, James E (IS) wrote:
&lt;br&gt;&amp;gt; &amp;gt; Hello,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I am trying to restrict an application to using only some interfaces
&lt;br&gt;&amp;gt; &amp;gt; on the system. I have defined a new type and assigned the interface
&lt;br&gt;&amp;gt; on
&lt;br&gt;&amp;gt; &amp;gt; my RHEL5.4-x64 system to the new type with semanage. The system
&lt;br&gt;&amp;gt; &amp;gt; indicates that the interface is now configured.
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;# semanage interface -l
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;SELinux Interface &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Context
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth1
&lt;br&gt;&amp;gt; system_u:object_r:iface_test_t:s0
&lt;br&gt;&amp;gt; &amp;gt; This does restrict applications like tcpdump or wireshark from
&lt;br&gt;&amp;gt; listing
&lt;br&gt;&amp;gt; &amp;gt; the interface that was configured.
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;# tcpdump -D
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.peth0
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.virbr0
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;3.vif0.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.eth0
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.xenbr0
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;6.eth2
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;7.eth3
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;8.any (Pseudo-device that captures on all interfaces)
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;9.lo
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; My problem comes that my application can still open eth1 and read
&lt;br&gt;&amp;gt; and
&lt;br&gt;&amp;gt; &amp;gt; write packets to this interface.
&lt;br&gt;&amp;gt; &amp;gt; The application is opening a socket as SOCK_RAW then binding with a
&lt;br&gt;&amp;gt; &amp;gt; struct sockaddr_LL that has the ssll_ifindex field configured with
&lt;br&gt;&amp;gt; the
&lt;br&gt;&amp;gt; &amp;gt; index of ETH1.
&lt;br&gt;&amp;gt; &amp;gt; How do I write a selinux policy to restrict this application from
&lt;br&gt;&amp;gt; &amp;gt; using some interfaces.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; In RHEL5 (Linux 2.6.18), you might need to enable compat_net (echo 1
&lt;br&gt;&amp;gt; &amp;gt; /selinux/compat_net or boot with selinux_compat_net=1 on the kernel
&lt;br&gt;&amp;gt; command line).
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Stephen Smalley
&lt;br&gt;&amp;gt; National Security Agency
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;-- 
&lt;br&gt;Stephen Smalley
&lt;br&gt;National Security Agency
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26812436&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/how-to-restrict-a-SOCK_RAW-by-interface-tp26783367p26812436.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26797534</id>
	<title>Re: Logrotate frustration</title>
	<published>2009-12-15T08:26:18Z</published>
	<updated>2009-12-15T08:26:18Z</updated>
	<author>
		<name>Arthur Dent-6</name>
	</author>
	<content type="html">On Tue, 2009-12-15 at 09:39 -0500, Daniel J Walsh wrote:
&lt;br&gt;&amp;gt; On 12/14/2009 05:01 AM, Arthur Dent wrote:
&lt;br&gt;&amp;gt; &amp;gt; On Mon, 2009-12-07 at 22:30 +0000, Arthur Dent wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt; On Mon, 2009-12-07 at 16:24 -0500, Daniel J Walsh wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; On 12/06/2009 04:38 AM, Arthur Dent wrote:
&lt;br&gt;&lt;br&gt;[Snip]
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; I can allow logrotate to manage log lnk_files, and allow it to write to the fail2ban socket.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Are you using a custom logrotate to rotate mail_spool?
&lt;br&gt;&lt;br&gt;[Snip]
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; OK - Following another arm of this thread I have (last week) done a
&lt;br&gt;&amp;gt; &amp;gt; complete relabel and removed my existing fail2ban and logrotate local
&lt;br&gt;&amp;gt; &amp;gt; policies.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; As a result of yesterday's weekly log rotate squid threw up another
&lt;br&gt;&amp;gt; &amp;gt; couple of AVCs related to log_lnk (see below).
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I have created another local policy but, do I understand you correctly
&lt;br&gt;&amp;gt; &amp;gt; Daniel that you may include log_lnk in a future targeted policy?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Here is my new logrotate policy:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; module mylogr 11.2.2;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type mail_spool_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type logrotate_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type squid_log_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class file getattr;
&lt;br&gt;&amp;gt; &amp;gt; 	class lnk_file { rename unlink };
&lt;br&gt;&amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; #============= logrotate_t ==============
&lt;br&gt;&amp;gt; &amp;gt; allow logrotate_t mail_spool_t:file getattr;
&lt;br&gt;&amp;gt; &amp;gt; allow logrotate_t squid_log_t:lnk_file { rename unlink };
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Is this OK?
&lt;/div&gt;&lt;/div&gt;[Snip]
&lt;br&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Yes the squid access will not be needed.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Fixed in selinux-policy-3.6.32-59.fc12.noarch
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; logrotate looking at /mnt/backup/mail/rawmail
&lt;br&gt;&amp;gt; Looks like a local customization.
&lt;br&gt;&lt;br&gt;Thanks Daniel,
&lt;br&gt;&lt;br&gt;OK - I am running F11:
&lt;br&gt;# rpm -qa | grep -i selinux-policy
&lt;br&gt;selinux-policy-targeted-3.6.12-91.fc11.noarch
&lt;br&gt;selinux-policy-3.6.12-91.fc11.noarch
&lt;br&gt;&lt;br&gt;Will there be a F11 version? (If so what version will it be in?)
&lt;br&gt;&lt;br&gt;In the meantime I should keep using my local policy I guess?...
&lt;br&gt;&lt;br&gt;Thanks again
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26797534&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26797534/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26797534.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26791621</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-15T00:55:59Z</published>
	<updated>2009-12-15T00:55:59Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 04:21:41PM -0800, David Highley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;AhhlLboLdkugWU4S&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=us-ascii
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=3Dpgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	protocol=3D&amp;quot;application/pgp-signature&amp;quot;; boundary=3D&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3Dutf-8
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful=
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp;and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true th=
&lt;br&gt;&amp;gt; &amp;gt; at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it =
&lt;br&gt;&amp;gt; &amp;gt; - bu=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; t perhaps I just wasn=3DE2=3D80=3D99t writing it right. &amp;nbsp;Is there a Ref=
&lt;br&gt;&amp;gt; &amp;gt; policy tut=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedor=
&lt;br&gt;&amp;gt; &amp;gt; a. M=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; Fedo=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D iptables_t =3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;type iptables_t;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;corecmd_read_bin_symlinks(iptables_t)&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;allow iptables_t self:fifo_file rw_fifo_file_perms;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newiptables.pp
&lt;br&gt;&amp;gt; &amp;gt; sudo semodule -i newiptables.pp
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D sshd_t =3D=3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;policy_module(newsshd, 1.0.0)&amp;quot; &amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;type sshd_t;&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;iptables_domtrans(sshd_t)&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; sudo semodule -i newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; This one is a bit more complicated because i dont know for sure what create=
&lt;br&gt;&amp;gt; &amp;gt; d it (in what context runs sshdfilter?)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;/div&gt;&lt;/div&gt;The two policy modules above try to fix the avc denials above. if you do not have mysshdfilter.pp installed then there is no need to install it now. But we do need to find a solution for the remaining avc denial that either of the two enclosed policy modules above do not fix.
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I also ment to ask if all three policy; mysshdfilter.pp, newiptables.pp,
&lt;br&gt;&amp;gt; and newsshd.pp; changes are needed?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;lt;trimmed audit log entries&amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; =3DtNuu
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3D&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; iEYEARECAAYFAksmrEAACgkQMlxVo39jgT/UPwCfexQ3gHxMcD3IFrFCeLSmqrQK
&lt;br&gt;&amp;gt; &amp;gt; 1wQAn1TK0UM7xl0MqMFwQbeBb6qr+cst
&lt;br&gt;&amp;gt; &amp;gt; =b5GU
&lt;br&gt;&amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791621&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26791621/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26791621.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26791582</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-15T00:52:28Z</published>
	<updated>2009-12-15T00:52:28Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 04:50:15PM -0800, David Highley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;quot;David Highley wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;AhhlLboLdkugWU4S&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=us-ascii
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=3Dpgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; 	protocol=3D&amp;quot;application/pgp-signature&amp;quot;; boundary=3D&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3Dutf-8
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;nbsp;and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true th=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it =
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; - bu=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; t perhaps I just wasn=3DE2=3D80=3D99t writing it right. &amp;nbsp;Is there a Ref=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; policy tut=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedor=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; a. M=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Fedo=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D iptables_t =3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;type iptables_t;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;corecmd_read_bin_symlinks(iptables_t)&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;allow iptables_t self:fifo_file rw_fifo_file_perms;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newiptables.pp
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Running the make for the above file ended up in an infinit loop
&lt;br&gt;&amp;gt; outputing:
&lt;br&gt;&amp;gt; myiptables.te:2: Warning: deprecated use of module name () as first
&lt;br&gt;&amp;gt; parameter of optional_policy() block.
&lt;/div&gt;&lt;/div&gt;Theres a syntax error or two:
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newiptables.te
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te 
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; sudo semodule -i newiptables.pp
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D sshd_t =3D=3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;policy_module(newsshd, 1.0.0)&amp;quot; &amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;type sshd_t;&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;iptables_domtrans(sshd_t)&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; sudo semodule -i newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; This one is a bit more complicated because i dont know for sure what create=
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; d it (in what context runs sshdfilter?)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I also ment to ask if all three policy; mysshdfilter.pp, newiptables.pp,
&lt;br&gt;&amp;gt; &amp;gt; and newsshd.pp; changes are needed?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;lt;trimmed audit log entries&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; =3DtNuu
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3D&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksmrEAACgkQMlxVo39jgT/UPwCfexQ3gHxMcD3IFrFCeLSmqrQK
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 1wQAn1TK0UM7xl0MqMFwQbeBb6qr+cst
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; =b5GU
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --AhhlLboLdkugWU4S--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --===============1862406356==--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26791582&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26791582/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26791582.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26787722</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T16:50:15Z</published>
	<updated>2009-12-14T16:50:15Z</updated>
	<author>
		<name>David Highley</name>
	</author>
	<content type="html">&amp;quot;David Highley wrote:&amp;quot;
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;AhhlLboLdkugWU4S&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=us-ascii
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=3Dpgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 	protocol=3D&amp;quot;application/pgp-signature&amp;quot;; boundary=3D&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3Dutf-8
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful=
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp;and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true th=
&lt;br&gt;&amp;gt; &amp;gt; at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it =
&lt;br&gt;&amp;gt; &amp;gt; - bu=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; t perhaps I just wasn=3DE2=3D80=3D99t writing it right. &amp;nbsp;Is there a Ref=
&lt;br&gt;&amp;gt; &amp;gt; policy tut=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedor=
&lt;br&gt;&amp;gt; &amp;gt; a. M=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; Fedo=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D iptables_t =3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;type iptables_t;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;corecmd_read_bin_symlinks(iptables_t)&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;allow iptables_t self:fifo_file rw_fifo_file_perms;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newiptables.pp
&lt;/div&gt;&lt;br&gt;Running the make for the above file ended up in an infinit loop
&lt;br&gt;outputing:
&lt;br&gt;myiptables.te:2: Warning: deprecated use of module name () as first
&lt;br&gt;parameter of optional_policy() block.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; sudo semodule -i newiptables.pp
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D sshd_t =3D=3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; &amp;gt; =3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;policy_module(newsshd, 1.0.0)&amp;quot; &amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;type sshd_t;&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;iptables_domtrans(sshd_t)&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; sudo semodule -i newsshd.pp
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; This one is a bit more complicated because i dont know for sure what create=
&lt;br&gt;&amp;gt; &amp;gt; d it (in what context runs sshdfilter?)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I also ment to ask if all three policy; mysshdfilter.pp, newiptables.pp,
&lt;br&gt;&amp;gt; and newsshd.pp; changes are needed?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;lt;trimmed audit log entries&amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; =3DtNuu
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3D&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; iEYEARECAAYFAksmrEAACgkQMlxVo39jgT/UPwCfexQ3gHxMcD3IFrFCeLSmqrQK
&lt;br&gt;&amp;gt; &amp;gt; 1wQAn1TK0UM7xl0MqMFwQbeBb6qr+cst
&lt;br&gt;&amp;gt; &amp;gt; =b5GU
&lt;br&gt;&amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --AhhlLboLdkugWU4S--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; --===============1862406356==--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787722&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26787722.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26787500</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T16:21:41Z</published>
	<updated>2009-12-14T16:21:41Z</updated>
	<author>
		<name>David Highley</name>
	</author>
	<content type="html">&amp;quot;Dominick Grift wrote:&amp;quot;
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;AhhlLboLdkugWU4S&amp;quot;
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=us-ascii
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=3Dpgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	protocol=3D&amp;quot;application/pgp-signature&amp;quot;; boundary=3D&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3Dutf-8
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful=
&lt;br&gt;&amp;gt; &amp;nbsp;and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true th=
&lt;br&gt;&amp;gt; at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it =
&lt;br&gt;&amp;gt; - bu=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; t perhaps I just wasn=3DE2=3D80=3D99t writing it right. &amp;nbsp;Is there a Ref=
&lt;br&gt;&amp;gt; policy tut=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedor=
&lt;br&gt;&amp;gt; a. M=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&lt;/a&gt;&lt;br&gt;&amp;gt; Fedo=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; &amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; &amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D iptables_t =3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; =3D=3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;type iptables_t;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;corecmd_read_bin_symlinks(iptables_t)&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;allow iptables_t self:fifo_file rw_fifo_file_perms;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; make -f /usr/share/selinux/devel/Makefile newiptables.pp
&lt;br&gt;&amp;gt; sudo semodule -i newiptables.pp
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D sshd_t =3D=3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; =3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; echo &amp;quot;policy_module(newsshd, 1.0.0)&amp;quot; &amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;type sshd_t;&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;iptables_domtrans(sshd_t)&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; make -f /usr/share/selinux/devel/Makefile newsshd.pp
&lt;br&gt;&amp;gt; sudo semodule -i newsshd.pp
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This one is a bit more complicated because i dont know for sure what create=
&lt;br&gt;&amp;gt; d it (in what context runs sshdfilter?)
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;/div&gt;&lt;br&gt;I also ment to ask if all three policy; mysshdfilter.pp, newiptables.pp,
&lt;br&gt;and newsshd.pp; changes are needed?
&lt;br&gt;&lt;br&gt;&amp;lt;trimmed audit log entries&amp;gt;
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787500&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; =3DtNuu
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3D&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787500&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787500&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --AhhlLboLdkugWU4S
&lt;br&gt;&amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; iEYEARECAAYFAksmrEAACgkQMlxVo39jgT/UPwCfexQ3gHxMcD3IFrFCeLSmqrQK
&lt;br&gt;&amp;gt; 1wQAn1TK0UM7xl0MqMFwQbeBb6qr+cst
&lt;br&gt;&amp;gt; =b5GU
&lt;br&gt;&amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --AhhlLboLdkugWU4S--
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============1862406356==
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787500&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; --===============1862406356==--
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787500&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26787500.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26787392</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T16:08:56Z</published>
	<updated>2009-12-14T16:08:56Z</updated>
	<author>
		<name>David Highley</name>
	</author>
	<content type="html">&amp;quot;Dominick Grift wrote:&amp;quot;
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============1736741946==
&lt;br&gt;&amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;2B/JsCI69OhZNC5r&amp;quot;
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --2B/JsCI69OhZNC5r
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=us-ascii
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=3Dpgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	protocol=3D&amp;quot;application/pgp-signature&amp;quot;; boundary=3D&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3Dutf-8
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful=
&lt;br&gt;&amp;gt; &amp;nbsp;and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true th=
&lt;br&gt;&amp;gt; at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it =
&lt;br&gt;&amp;gt; - bu=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; t perhaps I just wasn=3DE2=3D80=3D99t writing it right. &amp;nbsp;Is there a Ref=
&lt;br&gt;&amp;gt; policy tut=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedor=
&lt;br&gt;&amp;gt; a. M=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_=&lt;/a&gt;&lt;br&gt;&amp;gt; Fedo=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; &amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; &amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; &amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; &amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D iptables_t =3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; =3D=3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; &amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; #=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D sshd_t =3D=3D=3D=3D=3D=3D=3D=3D=
&lt;br&gt;&amp;gt; =3D=3D=3D=3D=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Actually i think sshdfilter init script may have created it? Does it even h=
&lt;br&gt;&amp;gt; ave an init script?
&lt;/div&gt;&lt;br&gt;Sorry, I think I confused the issue a little. I dumped in all the audit
&lt;br&gt;log entries related to the sshd filter wrapper script starting with no
&lt;br&gt;policy changes. I thought it might help to find the right policy
&lt;br&gt;changes.
&lt;br&gt;&lt;br&gt;The wrapper filter script does not have its own init script, we modify
&lt;br&gt;the sshd init script to invoke the wrapper script instead of sshd. This
&lt;br&gt;is some what bad in that package maintainers assume they can freely over
&lt;br&gt;write the init scripts and not break a site.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; The audit log entries are:
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259642932.902:7): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;=
&lt;br&gt;&amp;gt; pid=3D1411 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D117=
&lt;br&gt;&amp;gt; 98 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u:o=
&lt;br&gt;&amp;gt; bject_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259642932.902:7): arch=3Dc000003e syscall=3D5=
&lt;br&gt;&amp;gt; 9 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1562e28 a2=3D7fff837b3df0 =
&lt;br&gt;&amp;gt; a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D1411 auid=3D4294967295 uid=3D=
&lt;br&gt;&amp;gt; 0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(no=
&lt;br&gt;&amp;gt; ne) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsyste=
&lt;br&gt;&amp;gt; m_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259644707.700:73): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D1948 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D11=
&lt;br&gt;&amp;gt; 798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u:=
&lt;br&gt;&amp;gt; object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259644707.700:73): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D15694c8 a2=3D7fff837b3df0=
&lt;br&gt;&amp;gt; &amp;nbsp;a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D1948 auid=3D4294967295 uid=
&lt;br&gt;&amp;gt; =3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D=
&lt;br&gt;&amp;gt; (none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsy=
&lt;br&gt;&amp;gt; stem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259650605.247:84): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D2248 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D11=
&lt;br&gt;&amp;gt; 798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u:=
&lt;br&gt;&amp;gt; object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259650605.247:84): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1567828 a2=3D7fff837b3df0=
&lt;br&gt;&amp;gt; &amp;nbsp;a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D2248 auid=3D4294967295 uid=
&lt;br&gt;&amp;gt; =3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D=
&lt;br&gt;&amp;gt; (none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsy=
&lt;br&gt;&amp;gt; stem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259661894.420:113): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for=
&lt;br&gt;&amp;gt; &amp;nbsp; pid=3D2815 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D1=
&lt;br&gt;&amp;gt; 1798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u=
&lt;br&gt;&amp;gt; :object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259661894.420:113): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1566e28 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D2815 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259667665.966:123): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for=
&lt;br&gt;&amp;gt; &amp;nbsp; pid=3D3724 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D1=
&lt;br&gt;&amp;gt; 1798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u=
&lt;br&gt;&amp;gt; :object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259667665.966:123): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D15699d8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D3724 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259671660.048:131): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for=
&lt;br&gt;&amp;gt; &amp;nbsp; pid=3D3920 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D1=
&lt;br&gt;&amp;gt; 1798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u=
&lt;br&gt;&amp;gt; :object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259671660.048:131): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1565778 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D3920 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259673411.553:758): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for=
&lt;br&gt;&amp;gt; &amp;nbsp; pid=3D4558 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D1=
&lt;br&gt;&amp;gt; 1798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_u=
&lt;br&gt;&amp;gt; :object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259673411.553:758): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1569af8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D4558 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259679153.568:1267): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D5170 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259679153.568:1267): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1566a68 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D5170 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259682588.736:1315): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D5540 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259682588.736:1315): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1565778 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D5540 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259684861.197:1344): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D5745 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259684861.197:1344): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a478 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D5745 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259690558.951:1388): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D6161 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259690558.951:1388): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D15667a8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D6161 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259702647.573:1433): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D6829 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259702647.573:1433): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156b4d8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D6829 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259708100.231:1441): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D7085 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259708100.231:1441): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a0b8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D7085 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259708922.953:1450): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D7153 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259708922.953:1450): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a6a8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D7153 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259713257.803:1545): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D7492 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259713257.803:1545): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a4a8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D7492 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259721513.893:1732): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D8097 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259721513.893:1732): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a5d8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D8097 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259730724.196:1790): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D8689 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259730724.196:1790): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1569718 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D8689 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259730728.123:1793): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D8699 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259730728.123:1793): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D1566778 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D8699 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259747840.157:1835): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D9575 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D=
&lt;br&gt;&amp;gt; 11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsystem_=
&lt;br&gt;&amp;gt; u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259747840.157:1835): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156ba78 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D9575 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259760819.408:1863): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D10840 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsyst=
&lt;br&gt;&amp;gt; em_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259760819.408:1863): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff837b36b8 a1=3D156a4a8 a2=3D7fff837b3=
&lt;br&gt;&amp;gt; df0 a3=3D7fff837b3500 items=3D0 ppid=3D1402 pid=3D10840 auid=3D4294967295 u=
&lt;br&gt;&amp;gt; id=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259762576.442:1887): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D11067 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259762576.442:1887): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd4d5a8 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D11067 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259767362.673:1896): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D11318 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259767362.673:1896): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd54088 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D11318 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259773905.214:1967): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D11922 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259773905.214:1967): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd54868 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D11922 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259780362.196:1977): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D12215 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259780362.196:1977): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd50af8 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D12215 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259780393.314:1979): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D12219 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259780393.314:1979): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd50af8 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D12219 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259785085.323:2012): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D12568 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259785085.323:2012): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd521b8 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D12568 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259786872.756:2015): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D12645 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259786872.756:2015): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd53568 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D12645 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259795695.936:2052): avc: &amp;nbsp;denied &amp;nbsp;{ execute } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D13127 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259795695.936:2052): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffb91649e8 a1=3Dd52e38 a2=3D7fffb91651=
&lt;br&gt;&amp;gt; 20 a3=3D7fffb9164830 items=3D0 ppid=3D11058 pid=3D13127 auid=3D1000 uid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(non=
&lt;br&gt;&amp;gt; e) ses=3D47 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802506.518:3031): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } fo=
&lt;br&gt;&amp;gt; r &amp;nbsp;pid=3D11058 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; de=
&lt;br&gt;&amp;gt; v=3Ddm-0 ino=3D12538 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023=
&lt;br&gt;&amp;gt; &amp;nbsp;tcontext=3Dsystem_u:object_r:var_run_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802506.518:3031): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D6 success=3Dno exit=3D-13 a0=3Dd4a128 a1=3Da0d0a0 a2=3Da0d0a0 a3=3D7fffb=
&lt;br&gt;&amp;gt; 9164bb0 items=3D0 ppid=3D1 pid=3D11058 auid=3D1000 uid=3D0 gid=3D0 euid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D47 comm=
&lt;br&gt;&amp;gt; =3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:sshd_t:s=
&lt;br&gt;&amp;gt; 0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.332:7): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1435 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11021]&amp;quot; dev=3Dpipefs ino=3D11021=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.332:7): arch=3Dc000003e syscall=3D1=
&lt;br&gt;&amp;gt; 6 success=3Dyes exit=3D128 a0=3D3 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 items=
&lt;br&gt;&amp;gt; =3D0 ppid=3D1431 pid=3D1435 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=
&lt;br&gt;&amp;gt; =3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 co=
&lt;br&gt;&amp;gt; mm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t=
&lt;br&gt;&amp;gt; :s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.340:8): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1435 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11021]&amp;quot; dev=3Dpipefs ino=3D11021=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.340:8): arch=3Dc000003e syscall=3D1=
&lt;br&gt;&amp;gt; 6 success=3Dyes exit=3D128 a0=3D4 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 items=
&lt;br&gt;&amp;gt; =3D0 ppid=3D1431 pid=3D1435 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=
&lt;br&gt;&amp;gt; =3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 co=
&lt;br&gt;&amp;gt; mm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t=
&lt;br&gt;&amp;gt; :s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.342:9): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11031]&amp;quot; dev=3Dpipefs ino=3D11031=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.343:10): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1435 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11021]&amp;quot; dev=3Dpipefs ino=3D11021=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.343:10): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D3 a1=3Deb06e8 a2=3D1000 a3=3D0 items=3D0 pp=
&lt;br&gt;&amp;gt; id=3D1431 pid=3D1435 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fs=
&lt;br&gt;&amp;gt; uid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=
&lt;br&gt;&amp;gt; =3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.342:9): arch=3Dc000003e syscall=3D1=
&lt;br&gt;&amp;gt; 6 success=3Dyes exit=3D128 a0=3D5 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 items=
&lt;br&gt;&amp;gt; =3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=
&lt;br&gt;&amp;gt; =3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 co=
&lt;br&gt;&amp;gt; mm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t=
&lt;br&gt;&amp;gt; :s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.347:11): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11031]&amp;quot; dev=3Dpipefs ino=3D1103=
&lt;br&gt;&amp;gt; 1 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.347:11): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D6 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.350:12): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1439 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11031]&amp;quot; dev=3Dpipefs ino=3D11031=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.350:12): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D5 a1=3Deb0f18 a2=3D1000 a3=3D0 items=3D0 pp=
&lt;br&gt;&amp;gt; id=3D1438 pid=3D1439 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fs=
&lt;br&gt;&amp;gt; uid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=
&lt;br&gt;&amp;gt; =3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.360:13): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1440 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;sh&amp;quot; dev=3Ddm-0 ino=3D10258 scontext=3D=
&lt;br&gt;&amp;gt; system_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_t:s0 tclas=
&lt;br&gt;&amp;gt; s=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.360:13): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fd1ef909e0f a1=3D7fffa884e9b0 a2=3D7fffa88=
&lt;br&gt;&amp;gt; 511c0 a3=3D7fffa88507d0 items=3D0 ppid=3D1438 pid=3D1440 auid=3D4294967295 =
&lt;br&gt;&amp;gt; uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.364:14): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1440 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11043]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 3 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.364:14): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3Da a1=3D7fffa8850a0c a2=3D4 a3=3D7fffa885079=
&lt;br&gt;&amp;gt; 0 items=3D0 ppid=3D1438 pid=3D1440 auid=3D4294967295 uid=3D0 gid=3D0 euid=
&lt;br&gt;&amp;gt; =3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294=
&lt;br&gt;&amp;gt; 967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.367:15): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11043]&amp;quot; dev=3Dpipefs ino=3D11043=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.367:15): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D9 a1=3D7fffa8850ccc a2=3D4 a3=3Db73830 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.367:16): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11042]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 2 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.367:16): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7fffa8850a20 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.367:17): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11042]&amp;quot; dev=3Dpipefs ino=3D11042=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.367:17): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3Deb1168 a2=3D1000 a3=3D0 items=3D0 pp=
&lt;br&gt;&amp;gt; id=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fs=
&lt;br&gt;&amp;gt; uid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=
&lt;br&gt;&amp;gt; =3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.375:18): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1441 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;sh&amp;quot; dev=3Ddm-0 ino=3D10258 scontext=3D=
&lt;br&gt;&amp;gt; system_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_t:s0 tclas=
&lt;br&gt;&amp;gt; s=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.375:18): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fd1ef909e0f a1=3D7fffa884e9b0 a2=3D7fffa88=
&lt;br&gt;&amp;gt; 511c0 a3=3D7fffa88507d0 items=3D0 ppid=3D1438 pid=3D1441 auid=3D4294967295 =
&lt;br&gt;&amp;gt; uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.375:19): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1441 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11045]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 5 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.375:19): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3Da a1=3D7fffa8850a0c a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D1438 pid=3D1441 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=
&lt;br&gt;&amp;gt; =3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s=
&lt;br&gt;&amp;gt; 0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.378:20): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11045]&amp;quot; dev=3Dpipefs ino=3D11045=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.378:20): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D9 a1=3D7fffa8850ccc a2=3D4 a3=3D7fd1ef2e39d=
&lt;br&gt;&amp;gt; 0 items=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=
&lt;br&gt;&amp;gt; =3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294=
&lt;br&gt;&amp;gt; 967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.378:21): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11044]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 4 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.378:21): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7fffa8850a20 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.378:22): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11044]&amp;quot; dev=3Dpipefs ino=3D11044=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.378:22): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3Deb2878 a2=3D1000 a3=3D0 items=3D0 pp=
&lt;br&gt;&amp;gt; id=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fs=
&lt;br&gt;&amp;gt; uid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=
&lt;br&gt;&amp;gt; =3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.379:23): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11046]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 6 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.379:23): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.379:24): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11046]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 6 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.379:24): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D8 a1=3D5401 a2=3D7fffa8850c80 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1435 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.384:25): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1442 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11046]&amp;quot; dev=3Dpipefs ino=3D1104=
&lt;br&gt;&amp;gt; 6 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.384:25): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D4 a1=3D5401 a2=3D7fffa8850ba0 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D1438 pid=3D1442 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 c=
&lt;br&gt;&amp;gt; omm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_=
&lt;br&gt;&amp;gt; t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802888.384:26): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D1442 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11046]&amp;quot; dev=3Dpipefs ino=3D11=
&lt;br&gt;&amp;gt; 046 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r=
&lt;br&gt;&amp;gt; :iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802888.384:26): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 5 success=3Dyes exit=3D128 a0=3D4 a1=3Db730a0 a2=3Db730a0 a3=3D0 items=3D0 =
&lt;br&gt;&amp;gt; ppid=3D1438 pid=3D1442 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D=
&lt;br&gt;&amp;gt; &amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 k=
&lt;br&gt;&amp;gt; ey=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802889.381:27): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1494 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables&amp;quot; dev=3Ddm-0 ino=3D11793 scont=
&lt;br&gt;&amp;gt; ext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_t:s0=
&lt;br&gt;&amp;gt; &amp;nbsp;tclass=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802889.381:27): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fffa8850a88 a1=3Deb31c8 a2=3D7fffa88511c0 =
&lt;br&gt;&amp;gt; a3=3D7fffa88508d0 items=3D0 ppid=3D1438 pid=3D1494 auid=3D4294967295 uid=3D=
&lt;br&gt;&amp;gt; 0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(no=
&lt;br&gt;&amp;gt; ne) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsyste=
&lt;br&gt;&amp;gt; m_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802889.382:28): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1494 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11397]&amp;quot; dev=3Dpipefs ino=3D1139=
&lt;br&gt;&amp;gt; 7 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802889.382:28): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3D9 a1=3D7fffa8850b0c a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D1438 pid=3D1494 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=
&lt;br&gt;&amp;gt; =3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s=
&lt;br&gt;&amp;gt; 0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802889.385:29): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11397]&amp;quot; dev=3Dpipefs ino=3D11397=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802889.385:29): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D8 a1=3D7fffa8850f18 a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D1 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fs=
&lt;br&gt;&amp;gt; uid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=
&lt;br&gt;&amp;gt; =3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802889.388:30): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11021]&amp;quot; dev=3Dpipefs ino=3D1102=
&lt;br&gt;&amp;gt; 1 scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:i=
&lt;br&gt;&amp;gt; ptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802889.388:30): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3D4 a1=3Deb3248 a2=3D9 a3=3D0 items=3D0 ppid=
&lt;br&gt;&amp;gt; =3D1 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;sshd=
&lt;br&gt;&amp;gt; filter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259802889.390:31): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D1438 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[11046]&amp;quot; dev=3Dpipefs ino=3D11046=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dsystem_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:system_r:ip=
&lt;br&gt;&amp;gt; tables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259802889.390:31): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3Deb3568 a2=3D400 a3=3Db73010 items=3D=
&lt;br&gt;&amp;gt; 0 ppid=3D1 pid=3D1438 auid=3D4294967295 uid=3D0 gid=3D0 euid=3D0 suid=3D0 f=
&lt;br&gt;&amp;gt; suid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D4294967295 comm=3D&amp;quot;=
&lt;br&gt;&amp;gt; sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:iptables_t:s0 ke=
&lt;br&gt;&amp;gt; y=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.790:43): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2329 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24498]&amp;quot; dev=3Dpipefs ino=3D2449=
&lt;br&gt;&amp;gt; 8 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.790:43): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D4294967424 a0=3D3 a1=3D5401 a2=3D7ffffc393e40 a3=3D=
&lt;br&gt;&amp;gt; 60 items=3D0 ppid=3D2323 pid=3D2329 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 su=
&lt;br&gt;&amp;gt; id=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3Dpts0 ses=3D1 comm=3D&amp;quot;ssh=
&lt;br&gt;&amp;gt; dfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 k=
&lt;br&gt;&amp;gt; ey=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.795:44): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2329 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24498]&amp;quot; dev=3Dpipefs ino=3D2449=
&lt;br&gt;&amp;gt; 8 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.795:44): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D4294967424 a0=3D4 a1=3D5401 a2=3D7ffffc393e40 a3=3D=
&lt;br&gt;&amp;gt; 60 items=3D0 ppid=3D2323 pid=3D2329 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 su=
&lt;br&gt;&amp;gt; id=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3Dpts0 ses=3D1 comm=3D&amp;quot;ssh=
&lt;br&gt;&amp;gt; dfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 k=
&lt;br&gt;&amp;gt; ey=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.798:45): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24509]&amp;quot; dev=3Dpipefs ino=3D2450=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.801:46): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2329 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24498]&amp;quot; dev=3Dpipefs ino=3D24498=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.801:46): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D3 a1=3D104fb28 a2=3D1000 a3=3D0 items=3D0 p=
&lt;br&gt;&amp;gt; pid=3D2323 pid=3D2329 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3Dpts0 ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=
&lt;br&gt;&amp;gt; =3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.798:45): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D4294967424 a0=3D5 a1=3D5401 a2=3D7ffffc393e40 a3=3D=
&lt;br&gt;&amp;gt; 60 items=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 su=
&lt;br&gt;&amp;gt; id=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0=
&lt;br&gt;&amp;gt; &amp;nbsp;key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.804:47): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24509]&amp;quot; dev=3Dpipefs ino=3D2450=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.804:47): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D4294967424 a0=3D6 a1=3D5401 a2=3D7ffffc393e40 a3=3D=
&lt;br&gt;&amp;gt; 60 items=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 su=
&lt;br&gt;&amp;gt; id=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;s=
&lt;br&gt;&amp;gt; shdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0=
&lt;br&gt;&amp;gt; &amp;nbsp;key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.806:48): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2333 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24509]&amp;quot; dev=3Dpipefs ino=3D24509=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.812:49): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2334 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;sh&amp;quot; dev=3Ddm-0 ino=3D10258 scontext=3D=
&lt;br&gt;&amp;gt; unconfined_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_t:s0 t=
&lt;br&gt;&amp;gt; class=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.806:48): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D4294967424 a0=3D5 a1=3D1050268 a2=3D1000 a3=3D0 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2332 pid=3D2333 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.816:50): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24516]&amp;quot; dev=3Dpipefs ino=3D24516=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.812:49): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fceba680e0f a1=3D7ffffc391b70 a2=3D7ffffc3=
&lt;br&gt;&amp;gt; 94380 a3=3D7ffffc393990 items=3D0 ppid=3D2332 pid=3D2334 auid=3D1000 uid=3D=
&lt;br&gt;&amp;gt; 0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(no=
&lt;br&gt;&amp;gt; ne) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.816:51): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2334 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24516]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 6 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.816:51): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3Da a1=3D7ffffc393bcc a2=3D4 a3=3D7ffffc39395=
&lt;br&gt;&amp;gt; 0 items=3D0 ppid=3D2332 pid=3D2334 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;ss=
&lt;br&gt;&amp;gt; hdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 =
&lt;br&gt;&amp;gt; key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.816:50): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D9 a1=3D7ffffc393e8c a2=3D4 a3=3Dd13830 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.818:52): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24515]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 5 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.818:52): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7ffffc393be0 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.818:53): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24515]&amp;quot; dev=3Dpipefs ino=3D24515=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.818:53): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3D10504b8 a2=3D1000 a3=3D0 items=3D0 p=
&lt;br&gt;&amp;gt; pid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; e=
&lt;br&gt;&amp;gt; xe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.823:54): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2335 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;sh&amp;quot; dev=3Ddm-0 ino=3D10258 scontext=3D=
&lt;br&gt;&amp;gt; unconfined_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_t:s0 t=
&lt;br&gt;&amp;gt; class=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.823:54): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fceba680e0f a1=3D7ffffc391b70 a2=3D7ffffc3=
&lt;br&gt;&amp;gt; 94380 a3=3D7ffffc393990 items=3D0 ppid=3D2332 pid=3D2335 auid=3D1000 uid=3D=
&lt;br&gt;&amp;gt; 0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(no=
&lt;br&gt;&amp;gt; ne) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:s=
&lt;br&gt;&amp;gt; ystem_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.823:55): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2335 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24518]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 8 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.823:55): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3Da a1=3D7ffffc393bcc a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D2332 pid=3D2335 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; e=
&lt;br&gt;&amp;gt; xe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.828:56): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24518]&amp;quot; dev=3Dpipefs ino=3D24518=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.828:56): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D9 a1=3D7ffffc393e8c a2=3D4 a3=3D7fceba05a9d=
&lt;br&gt;&amp;gt; 0 items=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 sui=
&lt;br&gt;&amp;gt; d=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;ss=
&lt;br&gt;&amp;gt; hdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 =
&lt;br&gt;&amp;gt; key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.828:57): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24517]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 7 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.828:57): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7ffffc393be0 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.828:58): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24517]&amp;quot; dev=3Dpipefs ino=3D24517=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.828:58): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3D1051cc8 a2=3D1000 a3=3D0 items=3D0 p=
&lt;br&gt;&amp;gt; pid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; e=
&lt;br&gt;&amp;gt; xe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.833:59): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24519]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.833:59): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D7 a1=3D5401 a2=3D7ffffc393e40 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.833:60): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24519]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.833:60): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D8 a1=3D5401 a2=3D7ffffc393e40 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2329 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.834:61): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2336 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24519]&amp;quot; dev=3Dpipefs ino=3D2451=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.834:61): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 16 success=3Dyes exit=3D128 a0=3D4 a1=3D5401 a2=3D7ffffc393d60 a3=3D60 item=
&lt;br&gt;&amp;gt; s=3D0 ppid=3D2332 pid=3D2336 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 =
&lt;br&gt;&amp;gt; fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilt=
&lt;br&gt;&amp;gt; er&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D=
&lt;br&gt;&amp;gt; (null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803042.836:62): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D2336 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24519]&amp;quot; dev=3Dpipefs ino=3D24=
&lt;br&gt;&amp;gt; 519 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:=
&lt;br&gt;&amp;gt; system_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803042.836:62): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 5 success=3Dyes exit=3D128 a0=3D4 a1=3Dd130a0 a2=3Dd130a0 a3=3D0 items=3D0 =
&lt;br&gt;&amp;gt; ppid=3D2332 pid=3D2336 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; e=
&lt;br&gt;&amp;gt; xe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803043.839:63): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2338 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables&amp;quot; dev=3Ddm-0 ino=3D11793 scont=
&lt;br&gt;&amp;gt; ext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dsystem_u:object_r:bin_=
&lt;br&gt;&amp;gt; t:s0 tclass=3Dlnk_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803043.839:63): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7ffffc393c48 a1=3D1052638 a2=3D7ffffc394380=
&lt;br&gt;&amp;gt; &amp;nbsp;a3=3D7ffffc393a90 items=3D0 ppid=3D2332 pid=3D2338 auid=3D1000 uid=3D0 gid=
&lt;br&gt;&amp;gt; =3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) s=
&lt;br&gt;&amp;gt; es=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system=
&lt;br&gt;&amp;gt; _r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803043.840:64): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2338 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24549]&amp;quot; dev=3Dpipefs ino=3D2454=
&lt;br&gt;&amp;gt; 9 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803043.840:64): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3D9 a1=3D7ffffc393ccc a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D2332 pid=3D2338 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=
&lt;br&gt;&amp;gt; =3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; e=
&lt;br&gt;&amp;gt; xe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803043.844:65): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24549]&amp;quot; dev=3Dpipefs ino=3D24549=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803043.844:65): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D8 a1=3D7ffffc3940d8 a2=3D4 a3=3D8 items=3D0=
&lt;br&gt;&amp;gt; &amp;nbsp;ppid=3D1 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D=
&lt;br&gt;&amp;gt; 0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=
&lt;br&gt;&amp;gt; =3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803043.845:66): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;p=
&lt;br&gt;&amp;gt; id=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24498]&amp;quot; dev=3Dpipefs ino=3D2449=
&lt;br&gt;&amp;gt; 8 scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sy=
&lt;br&gt;&amp;gt; stem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803043.845:66): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 1 success=3Dyes exit=3D128 a0=3D4 a1=3D10526b8 a2=3D9 a3=3D0 items=3D0 ppid=
&lt;br&gt;&amp;gt; =3D1 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egi=
&lt;br&gt;&amp;gt; d=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/u=
&lt;br&gt;&amp;gt; sr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803043.849:67): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pi=
&lt;br&gt;&amp;gt; d=3D2332 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;pipe:[24519]&amp;quot; dev=3Dpipefs ino=3D24519=
&lt;br&gt;&amp;gt; &amp;nbsp;scontext=3Dunconfined_u:system_r:iptables_t:s0 tcontext=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:iptables_t:s0 tclass=3Dfifo_file
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803043.849:67): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 0 success=3Dyes exit=3D128 a0=3D7 a1=3D10529d8 a2=3D400 a3=3Dd13010 items=
&lt;br&gt;&amp;gt; =3D0 ppid=3D1 pid=3D2332 auid=3D1000 uid=3D0 gid=3D0 euid=3D0 suid=3D0 fsui=
&lt;br&gt;&amp;gt; d=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; =
&lt;br&gt;&amp;gt; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system_r:iptables_t:s0 key=3D(nul=
&lt;br&gt;&amp;gt; l)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259803128.077:69): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D2422 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D11=
&lt;br&gt;&amp;gt; 798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsyste=
&lt;br&gt;&amp;gt; m_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259803128.077:69): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fff14469168 a1=3D1c20208 a2=3D7fff144698a0=
&lt;br&gt;&amp;gt; &amp;nbsp;a3=3D7fff14468fb0 items=3D0 ppid=3D2413 pid=3D2422 auid=3D1000 uid=3D0 gid=
&lt;br&gt;&amp;gt; =3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) s=
&lt;br&gt;&amp;gt; es=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system=
&lt;br&gt;&amp;gt; _r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259806154.170:82): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for =
&lt;br&gt;&amp;gt; &amp;nbsp;pid=3D2653 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=3D11=
&lt;br&gt;&amp;gt; 798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsyste=
&lt;br&gt;&amp;gt; m_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259806154.170:82): arch=3Dc000003e syscall=3D=
&lt;br&gt;&amp;gt; 59 success=3Dno exit=3D-13 a0=3D7fff14469168 a1=3D1c267e8 a2=3D7fff144698a0=
&lt;br&gt;&amp;gt; &amp;nbsp;a3=3D7fff14468fb0 items=3D0 ppid=3D2413 pid=3D2653 auid=3D1000 uid=3D0 gid=
&lt;br&gt;&amp;gt; =3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) s=
&lt;br&gt;&amp;gt; es=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system=
&lt;br&gt;&amp;gt; _r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259812687.066:113): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D3074 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259812687.066:113): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff14469168 a1=3D1c26a88 a2=3D7fff14469=
&lt;br&gt;&amp;gt; 8a0 a3=3D7fff14468fb0 items=3D0 ppid=3D2413 pid=3D3074 auid=3D1000 uid=3D0 =
&lt;br&gt;&amp;gt; gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none=
&lt;br&gt;&amp;gt; ) ses=3D1 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:sys=
&lt;br&gt;&amp;gt; tem_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259816690.197:196): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D3631 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259816690.197:196): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff15c5a888 a1=3D24095a8 a2=3D7fff15c5a=
&lt;br&gt;&amp;gt; fc0 a3=3D7fff15c5a6d0 items=3D0 ppid=3D3622 pid=3D3631 auid=3D0 uid=3D0 gid=
&lt;br&gt;&amp;gt; =3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) s=
&lt;br&gt;&amp;gt; es=3D9 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system=
&lt;br&gt;&amp;gt; _r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259819529.773:214): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D3827 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259819529.773:214): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff15c5a888 a1=3D2410198 a2=3D7fff15c5a=
&lt;br&gt;&amp;gt; fc0 a3=3D7fff15c5a6d0 items=3D0 ppid=3D3622 pid=3D3827 auid=3D0 uid=3D0 gid=
&lt;br&gt;&amp;gt; =3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) s=
&lt;br&gt;&amp;gt; es=3D9 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:system=
&lt;br&gt;&amp;gt; _r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259899887.509:471): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D11794 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259899887.509:471): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff15c5a888 a1=3D2410198 a2=3D7fff15c5a=
&lt;br&gt;&amp;gt; fc0 a3=3D7fff15c5a6d0 items=3D0 ppid=3D3622 pid=3D11794 auid=3D0 uid=3D0 gi=
&lt;br&gt;&amp;gt; d=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) =
&lt;br&gt;&amp;gt; ses=3D9 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:syste=
&lt;br&gt;&amp;gt; m_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259899890.409:475): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D11799 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259899890.409:475): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff15c5a888 a1=3D2410548 a2=3D7fff15c5a=
&lt;br&gt;&amp;gt; fc0 a3=3D7fff15c5a6d0 items=3D0 ppid=3D3622 pid=3D11799 auid=3D0 uid=3D0 gi=
&lt;br&gt;&amp;gt; d=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) =
&lt;br&gt;&amp;gt; ses=3D9 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:syste=
&lt;br&gt;&amp;gt; m_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1259899950.600:483): avc: &amp;nbsp;denied &amp;nbsp;{ read open } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D11860 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1259899950.600:483): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff9722f198 a1=3Df6e208 a2=3D7fff9722f8=
&lt;br&gt;&amp;gt; d0 a3=3D7fff9722efe0 items=3D0 ppid=3D11851 pid=3D11860 auid=3D0 uid=3D0 gi=
&lt;br&gt;&amp;gt; d=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) =
&lt;br&gt;&amp;gt; ses=3D44 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:syst=
&lt;br&gt;&amp;gt; em_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260146847.427:1066): avc: &amp;nbsp;denied &amp;nbsp;{ read open } =
&lt;br&gt;&amp;gt; for &amp;nbsp;pid=3D28420 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260146847.427:1066): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff9722f198 a1=3Df71c88 a2=3D7fff9722f8=
&lt;br&gt;&amp;gt; d0 a3=3D7fff9722efe0 items=3D0 ppid=3D11851 pid=3D28420 auid=3D0 uid=3D0 gi=
&lt;br&gt;&amp;gt; d=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) =
&lt;br&gt;&amp;gt; ses=3D44 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:syst=
&lt;br&gt;&amp;gt; em_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260146850.722:1070): avc: &amp;nbsp;denied &amp;nbsp;{ read open } =
&lt;br&gt;&amp;gt; for &amp;nbsp;pid=3D28428 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 ino=
&lt;br&gt;&amp;gt; =3D11798 scontext=3Dunconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3D=
&lt;br&gt;&amp;gt; system_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260146850.722:1070): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff9722f198 a1=3Df72a28 a2=3D7fff9722f8=
&lt;br&gt;&amp;gt; d0 a3=3D7fff9722efe0 items=3D0 ppid=3D11851 pid=3D28428 auid=3D0 uid=3D0 gi=
&lt;br&gt;&amp;gt; d=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) =
&lt;br&gt;&amp;gt; ses=3D44 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dunconfined_u:syst=
&lt;br&gt;&amp;gt; em_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260500225.789:25455): avc: &amp;nbsp;denied &amp;nbsp;{ read open }=
&lt;br&gt;&amp;gt; &amp;nbsp;for &amp;nbsp;pid=3D21350 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 in=
&lt;br&gt;&amp;gt; o=3D11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsys=
&lt;br&gt;&amp;gt; tem_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260500225.789:25455): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff032b96b8 a1=3Dbdbd18 a2=3D7fff032b9d=
&lt;br&gt;&amp;gt; f0 a3=3D7fff032b9500 items=3D0 ppid=3D1441 pid=3D21350 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260500228.740:25459): avc: &amp;nbsp;denied &amp;nbsp;{ read open }=
&lt;br&gt;&amp;gt; &amp;nbsp;for &amp;nbsp;pid=3D21355 comm=3D&amp;quot;sshdfilter&amp;quot; name=3D&amp;quot;iptables-multi&amp;quot; dev=3Ddm-0 in=
&lt;br&gt;&amp;gt; o=3D11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=3Dsys=
&lt;br&gt;&amp;gt; tem_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260500228.740:25459): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fff032b96b8 a1=3Dbddc38 a2=3D7fff032b9d=
&lt;br&gt;&amp;gt; f0 a3=3D7fff032b9500 items=3D0 ppid=3D1441 pid=3D21355 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260500358.675:25470): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } f=
&lt;br&gt;&amp;gt; or &amp;nbsp;pid=3D1441 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; de=
&lt;br&gt;&amp;gt; v=3Ddm-0 ino=3D10948 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 tco=
&lt;br&gt;&amp;gt; ntext=3Dsystem_u:object_r:var_run_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260500358.675:25470): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D6 success=3Dno exit=3D-13 a0=3Dbd5dd8 a1=3D8980a0 a2=3D8980a0 a3=3D7fff0=
&lt;br&gt;&amp;gt; 32b9880 items=3D0 ppid=3D1 pid=3D1441 auid=3D4294967295 uid=3D0 gid=3D0 eui=
&lt;br&gt;&amp;gt; d=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=3D(none) ses=3D429=
&lt;br&gt;&amp;gt; 4967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=3Dsystem_u:system_r:=
&lt;br&gt;&amp;gt; sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt; type=3DAVC msg=3Daudit(1260809448.592:28614): avc: &amp;nbsp;denied &amp;nbsp;{ execute_no_=
&lt;br&gt;&amp;gt; trans } for &amp;nbsp;pid=3D23422 comm=3D&amp;quot;sshdfilter&amp;quot; path=3D&amp;quot;/sbin/iptables-multi&amp;quot; =
&lt;br&gt;&amp;gt; dev=3Ddm-0 ino=3D11798 scontext=3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 t=
&lt;br&gt;&amp;gt; context=3Dsystem_u:object_r:iptables_exec_t:s0 tclass=3Dfile
&lt;br&gt;&amp;gt; &amp;gt; type=3DSYSCALL msg=3Daudit(1260809448.592:28614): arch=3Dc000003e syscall=
&lt;br&gt;&amp;gt; =3D59 success=3Dno exit=3D-13 a0=3D7fffc0880288 a1=3De0c508 a2=3D7fffc08809=
&lt;br&gt;&amp;gt; c0 a3=3D7fffc08800d0 items=3D0 ppid=3D1432 pid=3D23422 auid=3D4294967295 ui=
&lt;br&gt;&amp;gt; d=3D0 gid=3D0 euid=3D0 suid=3D0 fsuid=3D0 egid=3D0 sgid=3D0 fsgid=3D0 tty=
&lt;br&gt;&amp;gt; =3D(none) ses=3D4294967295 comm=3D&amp;quot;sshdfilter&amp;quot; exe=3D&amp;quot;/usr/bin/perl&amp;quot; subj=
&lt;br&gt;&amp;gt; =3Dsystem_u:system_r:sshd_t:s0-s0:c0.c1023 key=3D(null)
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;=3D20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787392&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; =3DtNuu
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Type: text/plain; charset=3D&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787392&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D0725889959=3D=3D--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787392&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --2B/JsCI69OhZNC5r
&lt;br&gt;&amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; iEYEARECAAYFAksmr6kACgkQMlxVo39jgT9jLQCghHyybd+FAVhKuaco96Y0PkNV
&lt;br&gt;&amp;gt; VlcAnjcN8KmKKFlL5jFAWI5/US7VJmoB
&lt;br&gt;&amp;gt; =HL4+
&lt;br&gt;&amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --2B/JsCI69OhZNC5r--
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============1736741946==
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787392&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; --===============1736741946==--
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26787392&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26787392.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26786501</id>
	<title>RE: how to restrict a SOCK_RAW by interface</title>
	<published>2009-12-14T14:56:27Z</published>
	<updated>2009-12-14T14:56:27Z</updated>
	<author>
		<name>Cernak, James E (IS)</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 3.2//EN&quot;&gt;
&lt;HTML&gt;
&lt;HEAD&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=iso-8859-1&quot;&gt;
&lt;META NAME=&quot;Generator&quot; CONTENT=&quot;MS Exchange Server version 6.5.7654.12&quot;&gt;
&lt;TITLE&gt;RE: how to restrict a SOCK_RAW by interface&lt;/TITLE&gt;
&lt;/HEAD&gt;
&lt;BODY&gt;
&lt;!-- Converted from text/plain format --&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Hello,&lt;BR&gt;
&lt;BR&gt;
Thanks for the hint, However it does not solve my problem I still can read from eth0.&lt;BR&gt;
&lt;BR&gt;
I did have to add allow rules for netif_t:netif but my policy still does not allow iface_test_t.&lt;BR&gt;
&lt;BR&gt;
James&lt;BR&gt;
&lt;BR&gt;
&lt;BR&gt;
-----Original Message-----&lt;BR&gt;
From: Stephen Smalley [&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26786501&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sds@...&lt;/a&gt;]&lt;BR&gt;
Sent: Mon 12/14/2009 1:49 PM&lt;BR&gt;
To: Cernak, James E (IS)&lt;BR&gt;
Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26786501&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;&lt;BR&gt;
Subject: Re: how to restrict a SOCK_RAW by interface&lt;BR&gt;
&lt;BR&gt;
On Mon, 2009-12-14 at 13:29 -0600, Cernak, James E (IS) wrote:&lt;BR&gt;
&amp;gt; Hello,&lt;BR&gt;
&amp;gt;&lt;BR&gt;
&amp;gt; I am trying to restrict an application to using only some interfaces&lt;BR&gt;
&amp;gt; on the system. I have defined a new type and assigned the interface on&lt;BR&gt;
&amp;gt; my RHEL5.4-x64 system to the new type with semanage. The system&lt;BR&gt;
&amp;gt; indicates that the interface is now configured.&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # semanage interface -l&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELinux Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Context&lt;BR&gt;
&amp;gt;&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system_u:object_r:iface_test_t:s0&lt;BR&gt;
&amp;gt; This does restrict applications like tcpdump or wireshark from listing&lt;BR&gt;
&amp;gt; the interface that was configured.&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # tcpdump -D&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.peth0&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.virbr0&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.vif0.0&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.eth0&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.xenbr0&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.eth2&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7.eth3&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.any (Pseudo-device that captures on all interfaces)&lt;BR&gt;
&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9.lo&lt;BR&gt;
&amp;gt;&lt;BR&gt;
&amp;gt; My problem comes that my application can still open eth1 and read and&lt;BR&gt;
&amp;gt; write packets to this interface.&lt;BR&gt;
&amp;gt; The application is opening a socket as SOCK_RAW then binding with a&lt;BR&gt;
&amp;gt; struct sockaddr_LL that has the ssll_ifindex field configured with the&lt;BR&gt;
&amp;gt; index of ETH1.&lt;BR&gt;
&amp;gt; How do I write a selinux policy to restrict this application from&lt;BR&gt;
&amp;gt; using some interfaces.&lt;BR&gt;
&amp;gt;&lt;BR&gt;
&lt;BR&gt;
In RHEL5 (Linux 2.6.18), you might need to enable compat_net (echo 1&lt;BR&gt;
&amp;gt; /selinux/compat_net or boot with selinux_compat_net=1 on the kernel&lt;BR&gt;
command line).&lt;BR&gt;
&lt;BR&gt;
--&lt;BR&gt;
Stephen Smalley&lt;BR&gt;
National Security Agency&lt;BR&gt;
&lt;BR&gt;
&lt;BR&gt;
&lt;/FONT&gt;
&lt;/P&gt;

&lt;/BODY&gt;
&lt;/HTML&gt;&lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26786501&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/how-to-restrict-a-SOCK_RAW-by-interface-tp26783367p26786501.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26785321</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T13:35:39Z</published>
	<updated>2009-12-14T13:35:39Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=utf-8
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true that
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it - bu=
&lt;br&gt;&amp;gt; &amp;gt; t perhaps I just wasn=E2=80=99t writing it right. &amp;nbsp;Is there a Refpolicy tut=
&lt;br&gt;&amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedora. M=
&lt;br&gt;&amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; require {
&lt;br&gt;&amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= iptables_t ==============
&lt;br&gt;&amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= sshd_t ==============
&lt;br&gt;&amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&lt;br&gt;Actually i think sshdfilter init script may have created it? Does it even have an init script?
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The audit log entries are:
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259642932.902:7): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1411 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259642932.902:7): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1562e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1411 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259644707.700:73): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1948 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259644707.700:73): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15694c8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1948 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259650605.247:84): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2248 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259650605.247:84): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1567828 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2248 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259661894.420:113): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2815 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259661894.420:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2815 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259667665.966:123): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3724 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259667665.966:123): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15699d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3724 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259671660.048:131): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3920 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259671660.048:131): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3920 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259673411.553:758): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=4558 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259673411.553:758): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569af8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=4558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259679153.568:1267): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5170 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259679153.568:1267): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566a68 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5170 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259682588.736:1315): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5540 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259682588.736:1315): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5540 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259684861.197:1344): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5745 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259684861.197:1344): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a478 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5745 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259690558.951:1388): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6161 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259690558.951:1388): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15667a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6161 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259702647.573:1433): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6829 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259702647.573:1433): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156b4d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6829 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259708100.231:1441): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7085 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259708100.231:1441): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a0b8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7085 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259708922.953:1450): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7153 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259708922.953:1450): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a6a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7153 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259713257.803:1545): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7492 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259713257.803:1545): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7492 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259721513.893:1732): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8097 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259721513.893:1732): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a5d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8097 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259730724.196:1790): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8689 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259730724.196:1790): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569718 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8689 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259730728.123:1793): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8699 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259730728.123:1793): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8699 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259747840.157:1835): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=9575 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259747840.157:1835): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156ba78 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=9575 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259760819.408:1863): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=10840 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259760819.408:1863): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=10840 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259762576.442:1887): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11067 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259762576.442:1887): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d4d5a8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11067 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259767362.673:1896): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11318 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259767362.673:1896): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54088 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11318 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259773905.214:1967): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11922 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259773905.214:1967): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54868 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11922 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259780362.196:1977): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12215 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259780362.196:1977): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12215 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259780393.314:1979): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12219 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259780393.314:1979): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12219 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259785085.323:2012): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12568 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259785085.323:2012): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d521b8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12568 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259786872.756:2015): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12645 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259786872.756:2015): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d53568 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12645 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259795695.936:2052): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=13127 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259795695.936:2052): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d52e38 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=13127 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802506.518:3031): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=11058 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=12538 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802506.518:3031): arch=c000003e syscall=6 success=no exit=-13 a0=d4a128 a1=a0d0a0 a2=a0d0a0 a3=7fffb9164bb0 items=0 ppid=1 pid=11058 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.332:7): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.332:7): arch=c000003e syscall=16 success=yes exit=128 a0=3 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.340:8): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.340:8): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.342:9): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.343:10): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.343:10): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=eb06e8 a2=1000 a3=0 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.342:9): arch=c000003e syscall=16 success=yes exit=128 a0=5 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.347:11): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.347:11): arch=c000003e syscall=16 success=yes exit=128 a0=6 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.350:12): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1439 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.350:12): arch=c000003e syscall=0 success=yes exit=128 a0=5 a1=eb0f18 a2=1000 a3=0 items=0 ppid=1438 pid=1439 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.360:13): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.360:13): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.364:14): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.364:14): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=7fffa8850790 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:15): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:15): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=b73830 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:16): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:16): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:17): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:17): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb1168 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.375:18): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.375:18): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.375:19): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.375:19): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=8 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:20): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:20): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=7fd1ef2e39d0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:21): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:21): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:22): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:22): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb2878 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.379:23): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.379:23): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.379:24): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.379:24): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.384:25): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.384:25): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850ba0 a3=60 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.384:26): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.384:26): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=b730a0 a2=b730a0 a3=0 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.381:27): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.381:27): arch=c000003e syscall=59 success=no exit=-13 a0=7fffa8850a88 a1=eb31c8 a2=7fffa88511c0 a3=7fffa88508d0 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.382:28): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.382:28): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7fffa8850b0c a2=4 a3=8 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.385:29): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.385:29): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7fffa8850f18 a2=4 a3=8 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.388:30): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.388:30): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=eb3248 a2=9 a3=0 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.390:31): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.390:31): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb3568 a2=400 a3=b73010 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.790:43): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.790:43): arch=c000003e syscall=16 success=yes exit=4294967424 a0=3 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.795:44): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.795:44): arch=c000003e syscall=16 success=yes exit=4294967424 a0=4 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.798:45): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.801:46): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.801:46): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=104fb28 a2=1000 a3=0 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.798:45): arch=c000003e syscall=16 success=yes exit=4294967424 a0=5 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.804:47): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.804:47): arch=c000003e syscall=16 success=yes exit=4294967424 a0=6 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.806:48): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2333 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.812:49): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.806:48): arch=c000003e syscall=0 success=yes exit=4294967424 a0=5 a1=1050268 a2=1000 a3=0 items=0 ppid=2332 pid=2333 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.816:50): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.812:49): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.816:51): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.816:51): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=7ffffc393950 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.816:50): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=d13830 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.818:52): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.818:52): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.818:53): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.818:53): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10504b8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.823:54): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.823:54): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.823:55): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.823:55): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=8 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:56): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:56): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=7fceba05a9d0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:57): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:57): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:58): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:58): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=1051cc8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.833:59): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.833:59): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.833:60): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.833:60): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.834:61): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.834:61): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7ffffc393d60 a3=60 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.836:62): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.836:62): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=d130a0 a2=d130a0 a3=0 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.839:63): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.839:63): arch=c000003e syscall=59 success=no exit=-13 a0=7ffffc393c48 a1=1052638 a2=7ffffc394380 a3=7ffffc393a90 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.840:64): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.840:64): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7ffffc393ccc a2=4 a3=8 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.844:65): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.844:65): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7ffffc3940d8 a2=4 a3=8 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.845:66): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.845:66): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=10526b8 a2=9 a3=0 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.849:67): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.849:67): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10529d8 a2=400 a3=d13010 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803128.077:69): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2422 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803128.077:69): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c20208 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2422 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259806154.170:82): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2653 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259806154.170:82): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c267e8 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2653 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259812687.066:113): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3074 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259812687.066:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c26a88 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=3074 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259816690.197:196): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3631 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259816690.197:196): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=24095a8 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3631 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259819529.773:214): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3827 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259819529.773:214): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3827 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899887.509:471): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11794 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899887.509:471): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11794 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899890.409:475): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11799 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899890.409:475): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410548 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11799 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899950.600:483): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11860 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899950.600:483): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f6e208 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=11860 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260146847.427:1066): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28420 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260146847.427:1066): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f71c88 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28420 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260146850.722:1070): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28428 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260146850.722:1070): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f72a28 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28428 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500225.789:25455): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21350 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500225.789:25455): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bdbd18 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21350 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500228.740:25459): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21355 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500228.740:25459): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bddc38 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21355 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500358.675:25470): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=10948 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500358.675:25470): arch=c000003e syscall=6 success=no exit=-13 a0=bd5dd8 a1=8980a0 a2=8980a0 a3=7fff032b9880 items=0 ppid=1 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260809448.592:28614): avc: &amp;nbsp;denied &amp;nbsp;{ execute_no_trans } for &amp;nbsp;pid=23422 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/sbin/iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260809448.592:28614): arch=c000003e syscall=59 success=no exit=-13 a0=7fffc0880288 a1=e0c508 a2=7fffc08809c0 a3=7fffc08800d0 items=0 ppid=1432 pid=23422 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785321&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; =tNuu
&lt;br&gt;&amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785321&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785321&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785321&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26785321/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26785321.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26785098</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T13:21:06Z</published>
	<updated>2009-12-14T13:21:06Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 10:25:08AM -0800, David Highley wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;quot;Dominick Grift wrote:&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; &amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=utf-8
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true that
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it - bu=
&lt;br&gt;&amp;gt; &amp;gt; t perhaps I just wasn=E2=80=99t writing it right. &amp;nbsp;Is there a Refpolicy tut=
&lt;br&gt;&amp;gt; &amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I spend a little time today writing about the policy structure in Fedora. M=
&lt;br&gt;&amp;gt; &amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; ra_12.pdf
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;&amp;gt; grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; module mysshdfilter 1.0;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; require {
&lt;br&gt;&amp;gt; 	type var_run_t;
&lt;br&gt;&amp;gt; 	type iptables_exec_t;
&lt;br&gt;&amp;gt; 	type bin_t;
&lt;br&gt;&amp;gt; 	type sshd_t;
&lt;br&gt;&amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; 	class lnk_file read;
&lt;br&gt;&amp;gt; 	class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;gt; 	class fifo_file { read write ioctl getattr };
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= iptables_t ==============
&lt;br&gt;&amp;gt; allow iptables_t bin_t:lnk_file read;
&lt;br&gt;&amp;gt; allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;/div&gt;&lt;/div&gt;echo &amp;quot;policy_module(newiptables, 1.0.0)&amp;quot; &amp;gt; newuiptables.te
&lt;br&gt;echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;gen_require(\'&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;type iptables_t;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;corecmd_read_bin_symlinks(iptables_t)&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;allow iptables_t self:fifo_file rw_fifo_file_perms;&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newiptables.te
&lt;br&gt;&lt;br&gt;make -f /usr/share/selinux/devel/Makefile newiptables.pp
&lt;br&gt;sudo semodule -i newiptables.pp
&lt;br&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= sshd_t ==============
&lt;br&gt;&amp;gt; allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;&lt;br&gt;echo &amp;quot;policy_module(newsshd, 1.0.0)&amp;quot; &amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;type sshd_t;&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;iptables_domtrans(sshd_t)&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;echo &amp;quot;')&amp;quot; &amp;gt;&amp;gt; newsshd.te
&lt;br&gt;&lt;br&gt;make -f /usr/share/selinux/devel/Makefile newsshd.pp
&lt;br&gt;sudo semodule -i newsshd.pp
&lt;br&gt;&lt;br&gt;&amp;gt; allow sshd_t var_run_t:file getattr;
&lt;br&gt;&lt;br&gt;This one is a bit more complicated because i dont know for sure what created it (in what context runs sshdfilter?)
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The audit log entries are:
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259642932.902:7): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1411 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259642932.902:7): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1562e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1411 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259644707.700:73): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1948 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259644707.700:73): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15694c8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1948 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259650605.247:84): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2248 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259650605.247:84): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1567828 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2248 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259661894.420:113): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2815 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259661894.420:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2815 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259667665.966:123): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3724 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259667665.966:123): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15699d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3724 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259671660.048:131): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3920 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259671660.048:131): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3920 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259673411.553:758): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=4558 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259673411.553:758): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569af8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=4558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259679153.568:1267): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5170 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259679153.568:1267): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566a68 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5170 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259682588.736:1315): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5540 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259682588.736:1315): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5540 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259684861.197:1344): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5745 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259684861.197:1344): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a478 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5745 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259690558.951:1388): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6161 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259690558.951:1388): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15667a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6161 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259702647.573:1433): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6829 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259702647.573:1433): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156b4d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6829 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259708100.231:1441): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7085 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259708100.231:1441): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a0b8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7085 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259708922.953:1450): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7153 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259708922.953:1450): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a6a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7153 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259713257.803:1545): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7492 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259713257.803:1545): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7492 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259721513.893:1732): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8097 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259721513.893:1732): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a5d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8097 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259730724.196:1790): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8689 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259730724.196:1790): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569718 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8689 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259730728.123:1793): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8699 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259730728.123:1793): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8699 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259747840.157:1835): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=9575 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259747840.157:1835): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156ba78 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=9575 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259760819.408:1863): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=10840 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259760819.408:1863): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=10840 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259762576.442:1887): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11067 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259762576.442:1887): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d4d5a8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11067 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259767362.673:1896): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11318 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259767362.673:1896): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54088 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11318 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259773905.214:1967): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11922 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259773905.214:1967): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54868 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11922 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259780362.196:1977): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12215 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259780362.196:1977): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12215 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259780393.314:1979): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12219 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259780393.314:1979): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12219 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259785085.323:2012): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12568 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259785085.323:2012): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d521b8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12568 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259786872.756:2015): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12645 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259786872.756:2015): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d53568 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12645 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259795695.936:2052): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=13127 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259795695.936:2052): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d52e38 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=13127 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802506.518:3031): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=11058 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=12538 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802506.518:3031): arch=c000003e syscall=6 success=no exit=-13 a0=d4a128 a1=a0d0a0 a2=a0d0a0 a3=7fffb9164bb0 items=0 ppid=1 pid=11058 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.332:7): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.332:7): arch=c000003e syscall=16 success=yes exit=128 a0=3 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.340:8): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.340:8): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.342:9): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.343:10): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.343:10): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=eb06e8 a2=1000 a3=0 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.342:9): arch=c000003e syscall=16 success=yes exit=128 a0=5 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.347:11): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.347:11): arch=c000003e syscall=16 success=yes exit=128 a0=6 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.350:12): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1439 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.350:12): arch=c000003e syscall=0 success=yes exit=128 a0=5 a1=eb0f18 a2=1000 a3=0 items=0 ppid=1438 pid=1439 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.360:13): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.360:13): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.364:14): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.364:14): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=7fffa8850790 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:15): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:15): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=b73830 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:16): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:16): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.367:17): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.367:17): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb1168 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.375:18): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.375:18): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.375:19): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.375:19): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=8 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:20): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:20): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=7fd1ef2e39d0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:21): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:21): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.378:22): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.378:22): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb2878 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.379:23): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.379:23): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.379:24): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.379:24): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.384:25): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.384:25): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850ba0 a3=60 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802888.384:26): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802888.384:26): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=b730a0 a2=b730a0 a3=0 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.381:27): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.381:27): arch=c000003e syscall=59 success=no exit=-13 a0=7fffa8850a88 a1=eb31c8 a2=7fffa88511c0 a3=7fffa88508d0 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.382:28): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.382:28): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7fffa8850b0c a2=4 a3=8 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.385:29): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.385:29): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7fffa8850f18 a2=4 a3=8 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.388:30): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.388:30): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=eb3248 a2=9 a3=0 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259802889.390:31): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259802889.390:31): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb3568 a2=400 a3=b73010 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.790:43): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.790:43): arch=c000003e syscall=16 success=yes exit=4294967424 a0=3 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.795:44): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.795:44): arch=c000003e syscall=16 success=yes exit=4294967424 a0=4 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.798:45): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.801:46): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.801:46): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=104fb28 a2=1000 a3=0 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.798:45): arch=c000003e syscall=16 success=yes exit=4294967424 a0=5 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.804:47): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.804:47): arch=c000003e syscall=16 success=yes exit=4294967424 a0=6 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.806:48): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2333 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.812:49): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.806:48): arch=c000003e syscall=0 success=yes exit=4294967424 a0=5 a1=1050268 a2=1000 a3=0 items=0 ppid=2332 pid=2333 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.816:50): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.812:49): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.816:51): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.816:51): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=7ffffc393950 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.816:50): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=d13830 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.818:52): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.818:52): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.818:53): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.818:53): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10504b8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.823:54): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.823:54): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.823:55): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.823:55): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=8 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:56): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:56): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=7fceba05a9d0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:57): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:57): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.828:58): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.828:58): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=1051cc8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.833:59): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.833:59): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.833:60): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.833:60): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.834:61): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.834:61): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7ffffc393d60 a3=60 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803042.836:62): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803042.836:62): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=d130a0 a2=d130a0 a3=0 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.839:63): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.839:63): arch=c000003e syscall=59 success=no exit=-13 a0=7ffffc393c48 a1=1052638 a2=7ffffc394380 a3=7ffffc393a90 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.840:64): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.840:64): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7ffffc393ccc a2=4 a3=8 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.844:65): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.844:65): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7ffffc3940d8 a2=4 a3=8 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.845:66): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.845:66): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=10526b8 a2=9 a3=0 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803043.849:67): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803043.849:67): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10529d8 a2=400 a3=d13010 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259803128.077:69): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2422 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259803128.077:69): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c20208 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2422 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259806154.170:82): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2653 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259806154.170:82): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c267e8 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2653 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259812687.066:113): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3074 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259812687.066:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c26a88 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=3074 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259816690.197:196): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3631 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259816690.197:196): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=24095a8 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3631 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259819529.773:214): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3827 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259819529.773:214): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3827 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899887.509:471): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11794 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899887.509:471): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11794 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899890.409:475): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11799 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899890.409:475): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410548 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11799 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1259899950.600:483): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11860 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1259899950.600:483): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f6e208 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=11860 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260146847.427:1066): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28420 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260146847.427:1066): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f71c88 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28420 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260146850.722:1070): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28428 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260146850.722:1070): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f72a28 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28428 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500225.789:25455): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21350 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500225.789:25455): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bdbd18 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21350 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500228.740:25459): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21355 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500228.740:25459): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bddc38 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21355 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260500358.675:25470): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=10948 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260500358.675:25470): arch=c000003e syscall=6 success=no exit=-13 a0=bd5dd8 a1=8980a0 a2=8980a0 a3=7fff032b9880 items=0 ppid=1 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; type=AVC msg=audit(1260809448.592:28614): avc: &amp;nbsp;denied &amp;nbsp;{ execute_no_trans } for &amp;nbsp;pid=23422 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/sbin/iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;&amp;gt; type=SYSCALL msg=audit(1260809448.592:28614): arch=c000003e syscall=59 success=no exit=-13 a0=7fffc0880288 a1=e0c508 a2=7fffc08809c0 a3=7fffc08800d0 items=0 ppid=1432 pid=23422 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785098&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; &amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; &amp;gt; =tNuu
&lt;br&gt;&amp;gt; &amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; &amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; &amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; &amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785098&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; --===============0725889959==--
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785098&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26785098&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26785098/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26785098.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26783965</id>
	<title>Re: The SELinux Documentation Project</title>
	<published>2009-12-14T12:09:42Z</published>
	<updated>2009-12-14T12:09:42Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 12:32:01PM -0600, Serge E. Hallyn wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Quoting Dominick Grift (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783965&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;domg472@...&lt;/a&gt;):
&lt;br&gt;&amp;gt; &amp;gt; On Mon, Dec 14, 2009 at 11:49:15AM -0600, Serge E. Hallyn wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Quoting Joshua Brindle (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783965&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;method@...&lt;/a&gt;):
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Dominick Grift wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;On 11/27/2009 09:31 PM, Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;As we discussed at Linux Plumbers Conference during the 'Making SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;Easier to Use&amp;quot; talk we have some document deficiencies in the SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;project.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;snip&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;We have gotten some good contributions to the documentation project over
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;the last couple months but there is always more to do. I've updated the
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Documentation TODO at:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Documentation_TODO&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Documentation_TODO&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;with some docs we'd like written and some guidance on what the format
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;should be. Use cases would be particularly appreciated.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;If you haven't gone to the documentation wiki lately take a look at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Main_Page&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Main_Page&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;and see what's been added.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Thanks for the help of the contributors and hopefully this effort will
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;go a long way toward gaining users and keeping SELinux enabled.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783965&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Attached is a concept i wrote today about Locking down webapps with CGI.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;This was a topic in the todo list.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;Would be nice if someone could proof-read this and when
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt;modified/accepted publish it.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; It's a wiki :) Just put it up there and others can make
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; How are we to create an account to edit a page? &amp;nbsp;The 'Log in/Create
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Account' page doesn't seem to let me create an account?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; I'd like to add the recipe
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; useradd xa
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	semanage user -a -R user_r xa
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	semanage login -a -s xa xa
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; You would probably also need:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; cd /etc/selinux/targeted/contexts/users; cp user_u xa;
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; To make that work.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hmm - I didn't think in f10 or f11 I needed to, but good to
&lt;br&gt;&amp;gt; know, thanks!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Easier would probably be: useradd -Z user_u xa
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Excellent, didn't know about it and I like it :)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; or
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; useradd xa
&lt;br&gt;&amp;gt; &amp;gt; semanage login -m -s user_u -r s0-s0 xa
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I don't have a fedora system handy at the moment - is the help
&lt;br&gt;&amp;gt; documentation in semanage now context-sensitive (so
&lt;br&gt;&amp;gt; 'semanage login help' and 'semanage user help' give different,
&lt;br&gt;&amp;gt; briefer, more meaningful help)?
&lt;/div&gt;&lt;/div&gt;less meaningful i would say:
&lt;br&gt;&lt;br&gt;[root@localhost etc]# semanage login help
&lt;br&gt;/usr/sbin/semanage: Invalid command: semanage login help
&lt;br&gt;&lt;br&gt;[root@localhost etc]# semanage user help
&lt;br&gt;/usr/sbin/semanage: Invalid command: semanage user help
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; You should send an e-mail to james morris. He maintains the site and will add a login if you ask him.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; to lock user xa into its own selinux context to the recipes page.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; If someone else is willing to post it, all the better.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; modifications. There are actually a couple people who are decent at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; copy editing that have done some work on the wiki so if we get
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; technical content up there they can do what they do to clean it up.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; thanks,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -serge
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; thanks,
&lt;br&gt;&amp;gt; -serge
&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783965&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26783965/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/The-SELinux-Documentation-Project--Request-for-topics--tp25651714p26783965.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26783669</id>
	<title>Re: how to restrict a SOCK_RAW by interface</title>
	<published>2009-12-14T11:49:52Z</published>
	<updated>2009-12-14T11:49:52Z</updated>
	<author>
		<name>Stephen Smalley</name>
	</author>
	<content type="html">On Mon, 2009-12-14 at 13:29 -0600, Cernak, James E (IS) wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I am trying to restrict an application to using only some interfaces
&lt;br&gt;&amp;gt; on the system. I have defined a new type and assigned the interface on
&lt;br&gt;&amp;gt; my RHEL5.4-x64 system to the new type with semanage. The system
&lt;br&gt;&amp;gt; indicates that the interface is now configured.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;# semanage interface -l
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;SELinux Interface &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Context
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; system_u:object_r:iface_test_t:s0
&lt;br&gt;&amp;gt; This does restrict applications like tcpdump or wireshark from listing
&lt;br&gt;&amp;gt; the interface that was configured.
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;# tcpdump -D
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.peth0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.virbr0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;3.vif0.0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;4.eth0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;5.xenbr0
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;6.eth2
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;7.eth3
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;8.any (Pseudo-device that captures on all interfaces)
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;9.lo
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; My problem comes that my application can still open eth1 and read and
&lt;br&gt;&amp;gt; write packets to this interface.
&lt;br&gt;&amp;gt; The application is opening a socket as SOCK_RAW then binding with a
&lt;br&gt;&amp;gt; struct sockaddr_LL that has the ssll_ifindex field configured with the
&lt;br&gt;&amp;gt; index of ETH1.
&lt;br&gt;&amp;gt; How do I write a selinux policy to restrict this application from
&lt;br&gt;&amp;gt; using some interfaces.
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;In RHEL5 (Linux 2.6.18), you might need to enable compat_net (echo 1
&lt;br&gt;&amp;gt; /selinux/compat_net or boot with selinux_compat_net=1 on the kernel
&lt;br&gt;command line).
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Stephen Smalley
&lt;br&gt;National Security Agency
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783669&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/how-to-restrict-a-SOCK_RAW-by-interface-tp26783367p26783669.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26783367</id>
	<title>how to restrict a SOCK_RAW by interface</title>
	<published>2009-12-14T11:29:38Z</published>
	<updated>2009-12-14T11:29:38Z</updated>
	<author>
		<name>Cernak, James E (IS)</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 3.2//EN&quot;&gt;
&lt;HTML&gt;
&lt;HEAD&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=iso-8859-1&quot;&gt;
&lt;META NAME=&quot;Generator&quot; CONTENT=&quot;MS Exchange Server version 6.5.7654.12&quot;&gt;
&lt;TITLE&gt;how to restrict a SOCK_RAW by interface&lt;/TITLE&gt;
&lt;/HEAD&gt;
&lt;BODY&gt;
&lt;!-- Converted from text/plain format --&gt;

&lt;P&gt;&lt;FONT SIZE=2&gt;Hello,&lt;BR&gt;
&lt;BR&gt;
I am trying to restrict an application to using only some interfaces on the system. I have defined a new type and assigned the interface on my RHEL5.4-x64 system to the new type with semanage. The system indicates that the interface is now configured.&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # semanage interface -l&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SELinux Interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Context&lt;BR&gt;
&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eth1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; system_u:object_r:iface_test_t:s0&lt;BR&gt;
This does restrict applications like tcpdump or wireshark from listing the interface that was configured.&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; # tcpdump -D&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.peth0&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.virbr0&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.vif0.0&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4.eth0&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5.xenbr0&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 6.eth2&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7.eth3&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8.any (Pseudo-device that captures on all interfaces)&lt;BR&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9.lo&lt;BR&gt;
&lt;BR&gt;
My problem comes that my application can still open eth1 and read and write packets to this interface.&lt;BR&gt;
The application is opening a socket as SOCK_RAW then binding with a struct sockaddr_LL that has the ssll_ifindex field configured with the index of ETH1.&lt;BR&gt;
How do I write a selinux policy to restrict this application from using some interfaces.&lt;BR&gt;
&lt;BR&gt;
&lt;BR&gt;
Thanks&lt;BR&gt;
James Cernak&lt;BR&gt;
&amp;lt;James.Cernak`at`ngc.com&amp;gt;&lt;BR&gt;
&lt;BR&gt;
&lt;/FONT&gt;
&lt;/P&gt;

&lt;/BODY&gt;
&lt;/HTML&gt;&lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26783367&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/how-to-restrict-a-SOCK_RAW-by-interface-tp26783367p26783367.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26782522</id>
	<title>Re: The SELinux Documentation Project</title>
	<published>2009-12-14T10:32:01Z</published>
	<updated>2009-12-14T10:32:01Z</updated>
	<author>
		<name>Serge E. Hallyn</name>
	</author>
	<content type="html">Quoting Dominick Grift (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782522&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;domg472@...&lt;/a&gt;):
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Mon, Dec 14, 2009 at 11:49:15AM -0600, Serge E. Hallyn wrote:
&lt;br&gt;&amp;gt; &amp;gt; Quoting Joshua Brindle (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782522&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;method@...&lt;/a&gt;):
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Dominick Grift wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;On 11/27/2009 09:31 PM, Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;As we discussed at Linux Plumbers Conference during the 'Making SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;Easier to Use&amp;quot; talk we have some document deficiencies in the SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;project.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;snip&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;We have gotten some good contributions to the documentation project over
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;the last couple months but there is always more to do. I've updated the
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Documentation TODO at:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Documentation_TODO&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Documentation_TODO&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;with some docs we'd like written and some guidance on what the format
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;should be. Use cases would be particularly appreciated.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;If you haven't gone to the documentation wiki lately take a look at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Main_Page&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Main_Page&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;and see what's been added.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;Thanks for the help of the contributors and hopefully this effort will
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;go a long way toward gaining users and keeping SELinux enabled.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782522&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Attached is a concept i wrote today about Locking down webapps with CGI.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;This was a topic in the todo list.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;Would be nice if someone could proof-read this and when
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt;modified/accepted publish it.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; It's a wiki :) Just put it up there and others can make
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; How are we to create an account to edit a page? &amp;nbsp;The 'Log in/Create
&lt;br&gt;&amp;gt; &amp;gt; Account' page doesn't seem to let me create an account?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; I'd like to add the recipe
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; useradd xa
&lt;br&gt;&amp;gt; &amp;gt; 	semanage user -a -R user_r xa
&lt;br&gt;&amp;gt; &amp;gt; 	semanage login -a -s xa xa
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You would probably also need:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; cd /etc/selinux/targeted/contexts/users; cp user_u xa;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; To make that work.
&lt;/div&gt;&lt;br&gt;Hmm - I didn't think in f10 or f11 I needed to, but good to
&lt;br&gt;know, thanks!
&lt;br&gt;&lt;br&gt;&amp;gt; Easier would probably be: useradd -Z user_u xa
&lt;br&gt;&lt;br&gt;Excellent, didn't know about it and I like it :)
&lt;br&gt;&lt;br&gt;&amp;gt; or
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; useradd xa
&lt;br&gt;&amp;gt; semanage login -m -s user_u -r s0-s0 xa
&lt;br&gt;&lt;br&gt;I don't have a fedora system handy at the moment - is the help
&lt;br&gt;documentation in semanage now context-sensitive (so
&lt;br&gt;'semanage login help' and 'semanage user help' give different,
&lt;br&gt;briefer, more meaningful help)?
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; You should send an e-mail to james morris. He maintains the site and will add a login if you ask him.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; to lock user xa into its own selinux context to the recipes page.
&lt;br&gt;&amp;gt; &amp;gt; If someone else is willing to post it, all the better.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; modifications. There are actually a couple people who are decent at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; copy editing that have done some work on the wiki so if we get
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; technical content up there they can do what they do to clean it up.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; thanks,
&lt;br&gt;&amp;gt; &amp;gt; -serge
&lt;/div&gt;&lt;br&gt;thanks,
&lt;br&gt;-serge
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782522&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/The-SELinux-Documentation-Project--Request-for-topics--tp25651714p26782522.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26782402</id>
	<title>Re: Fedora 12 and unconfined_u sshdfilter</title>
	<published>2009-12-14T10:25:08Z</published>
	<updated>2009-12-14T10:25:08Z</updated>
	<author>
		<name>David Highley</name>
	</author>
	<content type="html">&amp;quot;Dominick Grift wrote:&amp;quot;
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; Content-Type: multipart/signed; micalg=pgp-sha1;
&lt;br&gt;&amp;gt; 	protocol=&amp;quot;application/pgp-signature&amp;quot;; boundary=&amp;quot;uAKRQypu60I7Lcqm&amp;quot;
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=utf-8
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: quoted-printable
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Mon, Dec 07, 2009 at 12:01:09PM +0000, Moray Henderson (ICT) wrote:
&lt;br&gt;&amp;gt; &amp;gt; James Carter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;Dan's example used Refpolicy interfaces. &amp;nbsp;Interfaces are very useful and
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;provide a better layer of abstraction, but they are just m4 macros,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;which have always been used in SELinux policy.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;Interfaces should be used as much as possible, but it is not true that
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;you can't mix the old and new ways.
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; Mixing the plain rules and the m4 macros didn't work when I tried it - bu=
&lt;br&gt;&amp;gt; t perhaps I just wasn=E2=80=99t writing it right. &amp;nbsp;Is there a Refpolicy tut=
&lt;br&gt;&amp;gt; orial anywhere?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I spend a little time today writing about the policy structure in Fedora. M=
&lt;br&gt;&amp;gt; aybe it can help you or others:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://82.197.205.60/~dgrift/stuff/Managing_a_SELinux_environment_with_Fedo=&lt;/a&gt;&lt;br&gt;&amp;gt; ra_12.pdf
&lt;/div&gt;&lt;br&gt;&lt;br&gt;Still have not mastered this one yet. Here is the policy file created by
&lt;br&gt;grep of /var/log/audit/audit.log file piped to audit2allow:
&lt;br&gt;&lt;br&gt;module mysshdfilter 1.0;
&lt;br&gt;&lt;br&gt;require {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type var_run_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type iptables_exec_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type bin_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type sshd_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type iptables_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class lnk_file read;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class file { read getattr open execute execute_no_trans };
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class fifo_file { read write ioctl getattr };
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;#============= iptables_t ==============
&lt;br&gt;allow iptables_t bin_t:lnk_file read;
&lt;br&gt;allow iptables_t self:fifo_file { read write ioctl getattr };
&lt;br&gt;&lt;br&gt;#============= sshd_t ==============
&lt;br&gt;allow sshd_t iptables_exec_t:file { read execute open execute_no_trans };
&lt;br&gt;allow sshd_t var_run_t:file getattr;
&lt;br&gt;&lt;br&gt;&lt;br&gt;The audit log entries are:
&lt;br&gt;type=AVC msg=audit(1259642932.902:7): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1411 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259642932.902:7): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1562e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1411 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259644707.700:73): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=1948 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259644707.700:73): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15694c8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=1948 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259650605.247:84): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2248 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259650605.247:84): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1567828 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2248 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259661894.420:113): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2815 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259661894.420:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566e28 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=2815 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259667665.966:123): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3724 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259667665.966:123): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15699d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3724 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259671660.048:131): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=3920 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259671660.048:131): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=3920 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259673411.553:758): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=4558 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259673411.553:758): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569af8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=4558 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259679153.568:1267): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5170 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259679153.568:1267): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566a68 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5170 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259682588.736:1315): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5540 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259682588.736:1315): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1565778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5540 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259684861.197:1344): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=5745 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259684861.197:1344): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a478 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=5745 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259690558.951:1388): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6161 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259690558.951:1388): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=15667a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6161 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259702647.573:1433): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=6829 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259702647.573:1433): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156b4d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=6829 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259708100.231:1441): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7085 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259708100.231:1441): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a0b8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7085 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259708922.953:1450): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7153 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259708922.953:1450): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a6a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7153 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259713257.803:1545): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=7492 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259713257.803:1545): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=7492 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259721513.893:1732): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8097 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259721513.893:1732): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a5d8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8097 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259730724.196:1790): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8689 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259730724.196:1790): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1569718 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8689 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259730728.123:1793): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=8699 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259730728.123:1793): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=1566778 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=8699 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259747840.157:1835): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=9575 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259747840.157:1835): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156ba78 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=9575 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259760819.408:1863): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=10840 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259760819.408:1863): arch=c000003e syscall=59 success=no exit=-13 a0=7fff837b36b8 a1=156a4a8 a2=7fff837b3df0 a3=7fff837b3500 items=0 ppid=1402 pid=10840 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259762576.442:1887): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11067 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259762576.442:1887): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d4d5a8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11067 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259767362.673:1896): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11318 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259767362.673:1896): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54088 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11318 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259773905.214:1967): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=11922 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259773905.214:1967): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d54868 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=11922 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259780362.196:1977): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12215 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259780362.196:1977): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12215 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259780393.314:1979): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12219 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259780393.314:1979): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d50af8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12219 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259785085.323:2012): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12568 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259785085.323:2012): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d521b8 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12568 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259786872.756:2015): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=12645 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259786872.756:2015): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d53568 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=12645 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259795695.936:2052): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=13127 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259795695.936:2052): arch=c000003e syscall=59 success=no exit=-13 a0=7fffb91649e8 a1=d52e38 a2=7fffb9165120 a3=7fffb9164830 items=0 ppid=11058 pid=13127 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802506.518:3031): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=11058 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=12538 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259802506.518:3031): arch=c000003e syscall=6 success=no exit=-13 a0=d4a128 a1=a0d0a0 a2=a0d0a0 a3=7fffb9164bb0 items=0 ppid=1 pid=11058 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=47 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.332:7): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.332:7): arch=c000003e syscall=16 success=yes exit=128 a0=3 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.340:8): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.340:8): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.342:9): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=AVC msg=audit(1259802888.343:10): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1435 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.343:10): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=eb06e8 a2=1000 a3=0 items=0 ppid=1431 pid=1435 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=SYSCALL msg=audit(1259802888.342:9): arch=c000003e syscall=16 success=yes exit=128 a0=5 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.347:11): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.347:11): arch=c000003e syscall=16 success=yes exit=128 a0=6 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.350:12): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1439 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11031]&amp;quot; dev=pipefs ino=11031 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.350:12): arch=c000003e syscall=0 success=yes exit=128 a0=5 a1=eb0f18 a2=1000 a3=0 items=0 ppid=1438 pid=1439 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.360:13): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.360:13): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.364:14): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1440 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.364:14): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=7fffa8850790 items=0 ppid=1438 pid=1440 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.367:15): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11043]&amp;quot; dev=pipefs ino=11043 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.367:15): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=b73830 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.367:16): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.367:16): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.367:17): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11042]&amp;quot; dev=pipefs ino=11042 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.367:17): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb1168 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.375:18): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.375:18): arch=c000003e syscall=59 success=no exit=-13 a0=7fd1ef909e0f a1=7fffa884e9b0 a2=7fffa88511c0 a3=7fffa88507d0 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.375:19): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.375:19): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7fffa8850a0c a2=4 a3=8 items=0 ppid=1438 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.378:20): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11045]&amp;quot; dev=pipefs ino=11045 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.378:20): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7fffa8850ccc a2=4 a3=7fd1ef2e39d0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.378:21): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.378:21): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850a20 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.378:22): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11044]&amp;quot; dev=pipefs ino=11044 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.378:22): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb2878 a2=1000 a3=0 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.379:23): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.379:23): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.379:24): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.379:24): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7fffa8850c80 a3=60 items=0 ppid=1435 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.384:25): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.384:25): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7fffa8850ba0 a3=60 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802888.384:26): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1442 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802888.384:26): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=b730a0 a2=b730a0 a3=0 items=0 ppid=1438 pid=1442 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802889.381:27): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259802889.381:27): arch=c000003e syscall=59 success=no exit=-13 a0=7fffa8850a88 a1=eb31c8 a2=7fffa88511c0 a3=7fffa88508d0 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802889.382:28): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1494 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802889.382:28): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7fffa8850b0c a2=4 a3=8 items=0 ppid=1438 pid=1494 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802889.385:29): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11397]&amp;quot; dev=pipefs ino=11397 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802889.385:29): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7fffa8850f18 a2=4 a3=8 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802889.388:30): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11021]&amp;quot; dev=pipefs ino=11021 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802889.388:30): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=eb3248 a2=9 a3=0 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259802889.390:31): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=1438 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[11046]&amp;quot; dev=pipefs ino=11046 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259802889.390:31): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=eb3568 a2=400 a3=b73010 items=0 ppid=1 pid=1438 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.790:43): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.790:43): arch=c000003e syscall=16 success=yes exit=4294967424 a0=3 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.795:44): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.795:44): arch=c000003e syscall=16 success=yes exit=4294967424 a0=4 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.798:45): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=AVC msg=audit(1259803042.801:46): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2329 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.801:46): arch=c000003e syscall=0 success=yes exit=128 a0=3 a1=104fb28 a2=1000 a3=0 items=0 ppid=2323 pid=2329 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=SYSCALL msg=audit(1259803042.798:45): arch=c000003e syscall=16 success=yes exit=4294967424 a0=5 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.804:47): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.804:47): arch=c000003e syscall=16 success=yes exit=4294967424 a0=6 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.806:48): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2333 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24509]&amp;quot; dev=pipefs ino=24509 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=AVC msg=audit(1259803042.812:49): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.806:48): arch=c000003e syscall=0 success=yes exit=4294967424 a0=5 a1=1050268 a2=1000 a3=0 items=0 ppid=2332 pid=2333 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.816:50): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.812:49): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.816:51): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2334 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24516]&amp;quot; dev=pipefs ino=24516 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.816:51): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=7ffffc393950 items=0 ppid=2332 pid=2334 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=SYSCALL msg=audit(1259803042.816:50): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=d13830 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.818:52): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.818:52): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.818:53): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24515]&amp;quot; dev=pipefs ino=24515 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.818:53): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10504b8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.823:54): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;sh&amp;quot; dev=dm-0 ino=10258 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.823:54): arch=c000003e syscall=59 success=no exit=-13 a0=7fceba680e0f a1=7ffffc391b70 a2=7ffffc394380 a3=7ffffc393990 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.823:55): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2335 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.823:55): arch=c000003e syscall=1 success=yes exit=128 a0=a a1=7ffffc393bcc a2=4 a3=8 items=0 ppid=2332 pid=2335 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.828:56): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24518]&amp;quot; dev=pipefs ino=24518 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.828:56): arch=c000003e syscall=0 success=yes exit=128 a0=9 a1=7ffffc393e8c a2=4 a3=7fceba05a9d0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.828:57): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.828:57): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393be0 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.828:58): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24517]&amp;quot; dev=pipefs ino=24517 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.828:58): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=1051cc8 a2=1000 a3=0 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.833:59): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.833:59): arch=c000003e syscall=16 success=yes exit=128 a0=7 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.833:60): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.833:60): arch=c000003e syscall=16 success=yes exit=128 a0=8 a1=5401 a2=7ffffc393e40 a3=60 items=0 ppid=2329 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.834:61): avc: &amp;nbsp;denied &amp;nbsp;{ ioctl } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.834:61): arch=c000003e syscall=16 success=yes exit=128 a0=4 a1=5401 a2=7ffffc393d60 a3=60 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803042.836:62): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=2336 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803042.836:62): arch=c000003e syscall=5 success=yes exit=128 a0=4 a1=d130a0 a2=d130a0 a3=0 items=0 ppid=2332 pid=2336 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803043.839:63): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables&amp;quot; dev=dm-0 ino=11793 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=system_u:object_r:bin_t:s0 tclass=lnk_file
&lt;br&gt;type=SYSCALL msg=audit(1259803043.839:63): arch=c000003e syscall=59 success=no exit=-13 a0=7ffffc393c48 a1=1052638 a2=7ffffc394380 a3=7ffffc393a90 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803043.840:64): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2338 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803043.840:64): arch=c000003e syscall=1 success=yes exit=128 a0=9 a1=7ffffc393ccc a2=4 a3=8 items=0 ppid=2332 pid=2338 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803043.844:65): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24549]&amp;quot; dev=pipefs ino=24549 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803043.844:65): arch=c000003e syscall=0 success=yes exit=128 a0=8 a1=7ffffc3940d8 a2=4 a3=8 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803043.845:66): avc: &amp;nbsp;denied &amp;nbsp;{ write } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24498]&amp;quot; dev=pipefs ino=24498 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803043.845:66): arch=c000003e syscall=1 success=yes exit=128 a0=4 a1=10526b8 a2=9 a3=0 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803043.849:67): avc: &amp;nbsp;denied &amp;nbsp;{ read } for &amp;nbsp;pid=2332 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;pipe:[24519]&amp;quot; dev=pipefs ino=24519 scontext=unconfined_u:system_r:iptables_t:s0 tcontext=unconfined_u:system_r:iptables_t:s0 tclass=fifo_file
&lt;br&gt;type=SYSCALL msg=audit(1259803043.849:67): arch=c000003e syscall=0 success=yes exit=128 a0=7 a1=10529d8 a2=400 a3=d13010 items=0 ppid=1 pid=2332 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:iptables_t:s0 key=(null)
&lt;br&gt;type=AVC msg=audit(1259803128.077:69): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2422 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259803128.077:69): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c20208 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2422 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259806154.170:82): avc: &amp;nbsp;denied &amp;nbsp;{ execute } for &amp;nbsp;pid=2653 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259806154.170:82): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c267e8 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=2653 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259812687.066:113): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3074 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259812687.066:113): arch=c000003e syscall=59 success=no exit=-13 a0=7fff14469168 a1=1c26a88 a2=7fff144698a0 a3=7fff14468fb0 items=0 ppid=2413 pid=3074 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259816690.197:196): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3631 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259816690.197:196): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=24095a8 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3631 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259819529.773:214): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=3827 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259819529.773:214): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=3827 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259899887.509:471): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11794 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259899887.509:471): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410198 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11794 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259899890.409:475): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11799 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259899890.409:475): arch=c000003e syscall=59 success=no exit=-13 a0=7fff15c5a888 a1=2410548 a2=7fff15c5afc0 a3=7fff15c5a6d0 items=0 ppid=3622 pid=11799 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=9 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1259899950.600:483): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=11860 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1259899950.600:483): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f6e208 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=11860 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260146847.427:1066): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28420 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260146847.427:1066): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f71c88 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28420 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260146850.722:1070): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=28428 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260146850.722:1070): arch=c000003e syscall=59 success=no exit=-13 a0=7fff9722f198 a1=f72a28 a2=7fff9722f8d0 a3=7fff9722efe0 items=0 ppid=11851 pid=28428 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=44 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260500225.789:25455): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21350 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260500225.789:25455): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bdbd18 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21350 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260500228.740:25459): avc: &amp;nbsp;denied &amp;nbsp;{ read open } for &amp;nbsp;pid=21355 comm=&amp;quot;sshdfilter&amp;quot; name=&amp;quot;iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260500228.740:25459): arch=c000003e syscall=59 success=no exit=-13 a0=7fff032b96b8 a1=bddc38 a2=7fff032b9df0 a3=7fff032b9500 items=0 ppid=1441 pid=21355 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260500358.675:25470): avc: &amp;nbsp;denied &amp;nbsp;{ getattr } for &amp;nbsp;pid=1441 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/var/run/sshdfilter.pid.SSHD&amp;quot; dev=dm-0 ino=10948 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260500358.675:25470): arch=c000003e syscall=6 success=no exit=-13 a0=bd5dd8 a1=8980a0 a2=8980a0 a3=7fff032b9880 items=0 ppid=1 pid=1441 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;type=AVC msg=audit(1260809448.592:28614): avc: &amp;nbsp;denied &amp;nbsp;{ execute_no_trans } for &amp;nbsp;pid=23422 comm=&amp;quot;sshdfilter&amp;quot; path=&amp;quot;/sbin/iptables-multi&amp;quot; dev=dm-0 ino=11798 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iptables_exec_t:s0 tclass=file
&lt;br&gt;type=SYSCALL msg=audit(1260809448.592:28614): arch=c000003e syscall=59 success=no exit=-13 a0=7fffc0880288 a1=e0c508 a2=7fffc08809c0 a3=7fffc08800d0 items=0 ppid=1432 pid=23422 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;sshdfilter&amp;quot; exe=&amp;quot;/usr/bin/perl&amp;quot; subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; Moray.
&lt;br&gt;&amp;gt; &amp;gt; &amp;quot;To err is human. &amp;nbsp;To purr, feline&amp;quot;
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt;=20
&lt;br&gt;&amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782402&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --uAKRQypu60I7Lcqm
&lt;br&gt;&amp;gt; Content-Type: application/pgp-signature
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; Version: GnuPG v1.4.10 (GNU/Linux)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; iEYEARECAAYFAksdZWwACgkQMlxVo39jgT/olgCgwo9wvxeAyJG/gm4dEYHBIpGf
&lt;br&gt;&amp;gt; TNEAn2bFoQZeg8+gaYPIDuB0wxuu6N8F
&lt;br&gt;&amp;gt; =tNuu
&lt;br&gt;&amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --uAKRQypu60I7Lcqm--
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --===============0725889959==
&lt;br&gt;&amp;gt; Content-Type: text/plain; charset=&amp;quot;us-ascii&amp;quot;
&lt;br&gt;&amp;gt; MIME-Version: 1.0
&lt;br&gt;&amp;gt; Content-Transfer-Encoding: 7bit
&lt;br&gt;&amp;gt; Content-Disposition: inline
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782402&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; --===============0725889959==--
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782402&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Fedora-12-and-unconfined_u-sshdfilter-tp26621281p26782402.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26782223</id>
	<title>Re: The SELinux Documentation Project</title>
	<published>2009-12-14T10:12:08Z</published>
	<updated>2009-12-14T10:12:08Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Mon, Dec 14, 2009 at 11:49:15AM -0600, Serge E. Hallyn wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Quoting Joshua Brindle (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782223&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;method@...&lt;/a&gt;):
&lt;br&gt;&amp;gt; &amp;gt; Dominick Grift wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;On 11/27/2009 09:31 PM, Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;As we discussed at Linux Plumbers Conference during the 'Making SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;Easier to Use&amp;quot; talk we have some document deficiencies in the SELinux
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;project.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;snip&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;We have gotten some good contributions to the documentation project over
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;the last couple months but there is always more to do. I've updated the
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;Documentation TODO at:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Documentation_TODO&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Documentation_TODO&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;with some docs we'd like written and some guidance on what the format
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;should be. Use cases would be particularly appreciated.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;If you haven't gone to the documentation wiki lately take a look at
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Main_Page&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Main_Page&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;and see what's been added.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;Thanks for the help of the contributors and hopefully this effort will
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;go a long way toward gaining users and keeping SELinux enabled.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;--
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782223&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;Attached is a concept i wrote today about Locking down webapps with CGI.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;This was a topic in the todo list.
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;Would be nice if someone could proof-read this and when
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt;modified/accepted publish it.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; It's a wiki :) Just put it up there and others can make
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; How are we to create an account to edit a page? &amp;nbsp;The 'Log in/Create
&lt;br&gt;&amp;gt; Account' page doesn't seem to let me create an account?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'd like to add the recipe
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; useradd xa
&lt;br&gt;&amp;gt; 	semanage user -a -R user_r xa
&lt;br&gt;&amp;gt; 	semanage login -a -s xa xa
&lt;/div&gt;&lt;/div&gt;You would probably also need:
&lt;br&gt;&lt;br&gt;cd /etc/selinux/targeted/contexts/users; cp user_u xa;
&lt;br&gt;&lt;br&gt;To make that work.
&lt;br&gt;&lt;br&gt;Easier would probably be: useradd -Z user_u xa
&lt;br&gt;&lt;br&gt;or
&lt;br&gt;&lt;br&gt;useradd xa
&lt;br&gt;semanage login -m -s user_u -r s0-s0 xa
&lt;br&gt;&lt;br&gt;You should send an e-mail to james morris. He maintains the site and will add a login if you ask him.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; to lock user xa into its own selinux context to the recipes page.
&lt;br&gt;&amp;gt; If someone else is willing to post it, all the better.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; modifications. There are actually a couple people who are decent at
&lt;br&gt;&amp;gt; &amp;gt; copy editing that have done some work on the wiki so if we get
&lt;br&gt;&amp;gt; &amp;gt; technical content up there they can do what they do to clean it up.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; thanks,
&lt;br&gt;&amp;gt; -serge
&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26782223&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26782223/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/The-SELinux-Documentation-Project--Request-for-topics--tp25651714p26782223.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26781872</id>
	<title>Re: The SELinux Documentation Project</title>
	<published>2009-12-14T09:49:15Z</published>
	<updated>2009-12-14T09:49:15Z</updated>
	<author>
		<name>Serge E. Hallyn</name>
	</author>
	<content type="html">Quoting Joshua Brindle (&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26781872&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;method@...&lt;/a&gt;):
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Dominick Grift wrote:
&lt;br&gt;&amp;gt; &amp;gt;On 11/27/2009 09:31 PM, Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;Joshua Brindle wrote:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;As we discussed at Linux Plumbers Conference during the 'Making SELinux
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;Easier to Use&amp;quot; talk we have some document deficiencies in the SELinux
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;project.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;lt;snip&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;We have gotten some good contributions to the documentation project over
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;the last couple months but there is always more to do. I've updated the
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;Documentation TODO at:
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Documentation_TODO&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Documentation_TODO&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;with some docs we'd like written and some guidance on what the format
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;should be. Use cases would be particularly appreciated.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;If you haven't gone to the documentation wiki lately take a look at
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&amp;lt;&lt;a href=&quot;http://selinuxproject.org/page/Main_Page&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://selinuxproject.org/page/Main_Page&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;and see what's been added.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;Thanks for the help of the contributors and hopefully this effort will
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;go a long way toward gaining users and keeping SELinux enabled.
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;--
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26781872&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt;&amp;gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;Attached is a concept i wrote today about Locking down webapps with CGI.
&lt;br&gt;&amp;gt; &amp;gt;This was a topic in the todo list.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt;Would be nice if someone could proof-read this and when
&lt;br&gt;&amp;gt; &amp;gt;modified/accepted publish it.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; It's a wiki :) Just put it up there and others can make
&lt;/div&gt;&lt;br&gt;How are we to create an account to edit a page? &amp;nbsp;The 'Log in/Create
&lt;br&gt;Account' page doesn't seem to let me create an account?
&lt;br&gt;&lt;br&gt;I'd like to add the recipe
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; useradd xa
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; semanage user -a -R user_r xa
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; semanage login -a -s xa xa
&lt;br&gt;&lt;br&gt;to lock user xa into its own selinux context to the recipes page.
&lt;br&gt;If someone else is willing to post it, all the better.
&lt;br&gt;&lt;br&gt;&amp;gt; modifications. There are actually a couple people who are decent at
&lt;br&gt;&amp;gt; copy editing that have done some work on the wiki so if we get
&lt;br&gt;&amp;gt; technical content up there they can do what they do to clean it up.
&lt;br&gt;&lt;br&gt;thanks,
&lt;br&gt;-serge
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26781872&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/The-SELinux-Documentation-Project--Request-for-topics--tp25651714p26781872.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26779260</id>
	<title>Re: ecryptfs selinux labeling on Fedora 12</title>
	<published>2009-12-14T07:05:27Z</published>
	<updated>2009-12-14T07:05:27Z</updated>
	<author>
		<name>Stephen Smalley</name>
	</author>
	<content type="html">On Mon, 2009-12-14 at 11:11 +0100, Roberto Sassu wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; i'm using Fedora12 and i have configured an ecryptfs filesystem.
&lt;br&gt;&amp;gt; I see that the default behaviour for this filesystem is to use an unique mount-
&lt;br&gt;&amp;gt; wide context (ecryptfs_t) to label each file.
&lt;br&gt;&amp;gt; There's a way to override this behaviour (for example by inserting a mount 
&lt;br&gt;&amp;gt; parameter), in order to use the extended attributes on the lower filesystem or 
&lt;br&gt;&amp;gt; patching the distributed selinux policy is the only option possible?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks in advance for replies.
&lt;/div&gt;&lt;br&gt;You'd have to modify, rebuild, and replace the base policy module to
&lt;br&gt;specify fs_use_xattr for ecryptfs rather than genfscon. &amp;nbsp;There was an
&lt;br&gt;attempt to automate probing for xattr support and use it if present, but
&lt;br&gt;it ran into problems, see:
&lt;br&gt;&lt;a href=&quot;http://marc.info/?t=121379726100001&amp;r=1&amp;w=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://marc.info/?t=121379726100001&amp;r=1&amp;w=2&lt;/a&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Stephen Smalley
&lt;br&gt;National Security Agency
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26779260&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/ecryptfs-selinux-labeling-on-Fedora-12-tp26775572p26779260.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26775572</id>
	<title>ecryptfs selinux labeling on Fedora 12</title>
	<published>2009-12-14T02:11:04Z</published>
	<updated>2009-12-14T02:11:04Z</updated>
	<author>
		<name>Roberto Sassu-2</name>
	</author>
	<content type="html">Hi all
&lt;br&gt;&lt;br&gt;i'm using Fedora12 and i have configured an ecryptfs filesystem.
&lt;br&gt;I see that the default behaviour for this filesystem is to use an unique mount-
&lt;br&gt;wide context (ecryptfs_t) to label each file.
&lt;br&gt;There's a way to override this behaviour (for example by inserting a mount 
&lt;br&gt;parameter), in order to use the extended attributes on the lower filesystem or 
&lt;br&gt;patching the distributed selinux policy is the only option possible?
&lt;br&gt;&lt;br&gt;Thanks in advance for replies.
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26775572&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (2K) &lt;a href=&quot;http://old.nabble.com/attachment/26775572/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/ecryptfs-selinux-labeling-on-Fedora-12-tp26775572p26775572.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26775422</id>
	<title>Re: Logrotate frustration</title>
	<published>2009-12-14T02:01:07Z</published>
	<updated>2009-12-14T02:01:07Z</updated>
	<author>
		<name>Arthur Dent-6</name>
	</author>
	<content type="html">On Mon, 2009-12-07 at 22:30 +0000, Arthur Dent wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Mon, 2009-12-07 at 16:24 -0500, Daniel J Walsh wrote:
&lt;br&gt;&amp;gt; &amp;gt; On 12/06/2009 04:38 AM, Arthur Dent wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Hello all,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Its seems that almost every week logrotate is throwing up a new AVC. I
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; have an almost vanilla F11 install with most packages installed via yum
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; and yet I keep getting these. Each time I audit2allow and build a new
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; policy. My &amp;quot;mylogr.te&amp;quot; is now at version 7. Am I missing a bool or is
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; there something else I'm lacking?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Here is the latest version of my policy:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; module mylogr 11.1.7;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; require {
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type mail_spool_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type logrotate_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type fail2ban_var_run_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type initrc_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	type squid_log_t;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class dir {read open write remove_name};
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class file { getattr read write open};
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class file setattr;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class sock_file write;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class unix_stream_socket connectto;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	class lnk_file rename;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; }
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; #============= logrotate_t ==============
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t mail_spool_t:file { getattr read write open };
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t mail_spool_t:dir { read open write remove_name};
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t mail_spool_t:file setattr;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t fail2ban_var_run_t:sock_file write;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t initrc_t:unix_stream_socket connectto;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; allow logrotate_t squid_log_t:lnk_file rename;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; This was today's AVC that necessitated the inclusion of the squid stuff:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; node=mydomain.org.uk type=AVC msg=audit(1260069452.494:45041): avc: denied { rename } for pid=12302 comm=&amp;quot;logrotate&amp;quot; name=&amp;quot;squidGuard.log&amp;quot; dev=sda5 ino=387195 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:squid_log_t:s0 tclass=lnk_file 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; node=mydomain.org.uk type=SYSCALL msg=audit(1260069452.494:45041): arch=40000003 syscall=38 success=no exit=-13 a0=890b130 a1=8908760 a2=890b060 a3=0 items=0 ppid=12300 pid=12302 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=2275 comm=&amp;quot;logrotate&amp;quot; exe=&amp;quot;/usr/sbin/logrotate&amp;quot; subj=system_u:system_r:logrotate_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ===============8&amp;lt;==================================================
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; --
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26775422&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; I can allow logrotate to manage log lnk_files, and allow it to write to the fail2ban socket.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Are you using a custom logrotate to rotate mail_spool?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Why is 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I think that my problem with mailspool/logrotate is that it relates to
&lt;br&gt;&amp;gt; my mail backup system in which procmail places a copy of every mail (in
&lt;br&gt;&amp;gt; mbox format) onto a separate partition on the same machine. This seemed
&lt;br&gt;&amp;gt; to cause labelling problems and we went round the houses on this issue a
&lt;br&gt;&amp;gt; while back (&amp;quot;Partitions Mounted by fstab&amp;quot; 5 March 2008 -
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/archives/fedora-selinux-list/2008-March/msg00030.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/archives/fedora-selinux-list/2008-March/msg00030.html&lt;/a&gt;)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks for your help - much appreciated...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Mark
&lt;/div&gt;&lt;/div&gt;OK - Following another arm of this thread I have (last week) done a
&lt;br&gt;complete relabel and removed my existing fail2ban and logrotate local
&lt;br&gt;policies.
&lt;br&gt;&lt;br&gt;As a result of yesterday's weekly log rotate squid threw up another
&lt;br&gt;couple of AVCs related to log_lnk (see below).
&lt;br&gt;&lt;br&gt;I have created another local policy but, do I understand you correctly
&lt;br&gt;Daniel that you may include log_lnk in a future targeted policy?
&lt;br&gt;&lt;br&gt;Here is my new logrotate policy:
&lt;br&gt;&lt;br&gt;===============8&amp;lt;==================================================
&lt;br&gt;&lt;br&gt;module mylogr 11.2.2;
&lt;br&gt;&lt;br&gt;require {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type mail_spool_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type logrotate_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type squid_log_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class file getattr;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class lnk_file { rename unlink };
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;#============= logrotate_t ==============
&lt;br&gt;allow logrotate_t mail_spool_t:file getattr;
&lt;br&gt;allow logrotate_t squid_log_t:lnk_file { rename unlink };
&lt;br&gt;&lt;br&gt;===============8&amp;lt;==================================================
&lt;br&gt;&lt;br&gt;Is this OK?
&lt;br&gt;&lt;br&gt;Thanks for any help or suggestions...
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br&gt;p.s.
&lt;br&gt;&lt;br&gt;Logrotate AVCs
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260331775.761:1220): avc: denied { getattr } for pid=31349 comm=&amp;quot;logrotate&amp;quot; path=&amp;quot;/mnt/backup/mail/rawmail&amp;quot; dev=sda9 ino=2490369 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mail_spool_t:s0 tclass=file 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260331775.761:1220): arch=40000003 syscall=196 success=yes exit=0 a0=9e59668 a1=bfd3e864 a2=bf5ff4 a3=1 items=0 ppid=31347 pid=31349 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=257 comm=&amp;quot;logrotate&amp;quot; exe=&amp;quot;/usr/sbin/logrotate&amp;quot; subj=system_u:system_r:logrotate_t:s0-s0:c0.c1023 key=(null) 
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260675470.813:43484): avc: denied { rename } for pid=11490 comm=&amp;quot;logrotate&amp;quot; name=&amp;quot;squidGuard.log&amp;quot; dev=sda5 ino=387195 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:squid_log_t:s0 tclass=lnk_file 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260675470.813:43484): arch=40000003 syscall=38 success=yes exit=0 a0=8295138 a1=8298f98 a2=8295068 a3=0 items=0 ppid=11488 pid=11490 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1554 comm=&amp;quot;logrotate&amp;quot; exe=&amp;quot;/usr/sbin/logrotate&amp;quot; subj=system_u:system_r:logrotate_t:s0-s0:c0.c1023 key=(null)
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260675471.68:43485): avc: denied { unlink } for pid=11490 comm=&amp;quot;logrotate&amp;quot; name=&amp;quot;squidGuard.log.1&amp;quot; dev=sda5 ino=387195 scontext=system_u:system_r:logrotate_t:s0-s0:c0.c1023 tcontext=system_u:object_r:squid_log_t:s0 tclass=lnk_file 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260675471.68:43485): arch=40000003 syscall=10 success=yes exit=0 a0=8298f98 a1=bfbeffa8 a2=8298f98 a3=bfbeff70 items=0 ppid=11488 pid=11490 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1554 comm=&amp;quot;logrotate&amp;quot; exe=&amp;quot;/usr/sbin/logrotate&amp;quot; subj=system_u:system_r:logrotate_t:s0-s0:c0.c1023 key=(null) 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26775422&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26775422/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26775422.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26739257</id>
	<title>Re: sebools are getting reset on reboot</title>
	<published>2009-12-10T22:13:51Z</published>
	<updated>2009-12-10T22:13:51Z</updated>
	<author>
		<name>Bruno Wolff III</name>
	</author>
	<content type="html">On Thu, Dec 10, 2009 at 19:22:59 -0800,
&lt;br&gt;&amp;nbsp; David Highley &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26739257&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dhighley@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Is this a bug? The two sebools, httpd_unified and
&lt;br&gt;&amp;gt; httpd_can_network_connect, are getting changed on policy updates and or
&lt;br&gt;&amp;gt; reboots.
&lt;br&gt;&lt;br&gt;Are you using the -P option when using the setsebool command? If you are
&lt;br&gt;using setsebool without it, then it is expected to reset on the next reboot.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26739257&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/sebools-are-getting-reset-on-reboot-tp26738156p26739257.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26738156</id>
	<title>sebools are getting reset on reboot</title>
	<published>2009-12-10T19:22:59Z</published>
	<updated>2009-12-10T19:22:59Z</updated>
	<author>
		<name>David Highley</name>
	</author>
	<content type="html">Is this a bug? The two sebools, httpd_unified and
&lt;br&gt;httpd_can_network_connect, are getting changed on policy updates and or
&lt;br&gt;reboots.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26738156&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/sebools-are-getting-reset-on-reboot-tp26738156p26738156.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26736312</id>
	<title>Re: Targeted Daemons/Apps- Fedora 12</title>
	<published>2009-12-10T15:26:02Z</published>
	<updated>2009-12-10T15:26:02Z</updated>
	<author>
		<name>Jorge Fábregas-3</name>
	</author>
	<content type="html">Thank you Daniel. &amp;nbsp;That's right on.
&lt;br&gt;&lt;br&gt;All the best,
&lt;br&gt;Jorge
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26736312&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Targeted-Daemons-Apps--Fedora-12-tp26693116p26736312.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26718233</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-09T13:41:55Z</published>
	<updated>2009-12-09T13:41:55Z</updated>
	<author>
		<name>Daniel J Walsh</name>
	</author>
	<content type="html">On 12/09/2009 02:37 PM, Göran Uddeborg wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Arthur Dent:
&lt;br&gt;&amp;gt;&amp;gt; How can I explain this to the f2b developers so that it can be fixed?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; For your information: I filed a bug about it a little more than a year
&lt;br&gt;&amp;gt; ago:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://sourceforge.net/tracker/?func=detail&amp;atid=689044&amp;aid=2086568&amp;group_id=121032&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/tracker/?func=detail&amp;atid=689044&amp;aid=2086568&amp;group_id=121032&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There hasn't been any action as far as I can tell. &amp;nbsp;But maybe you'll
&lt;br&gt;&amp;gt; have more luck if you do a new try now.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26718233&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;Fail2ban developers are well aware of this, they have been dealing with leaks for a while
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26718233&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26718233.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26716328</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-09T11:37:07Z</published>
	<updated>2009-12-09T11:37:07Z</updated>
	<author>
		<name>Göran Uddeborg</name>
	</author>
	<content type="html">Arthur Dent:
&lt;br&gt;&amp;gt; How can I explain this to the f2b developers so that it can be fixed?
&lt;br&gt;&lt;br&gt;For your information: I filed a bug about it a little more than a year
&lt;br&gt;ago:
&lt;br&gt;&lt;a href=&quot;http://sourceforge.net/tracker/?func=detail&amp;atid=689044&amp;aid=2086568&amp;group_id=121032&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sourceforge.net/tracker/?func=detail&amp;atid=689044&amp;aid=2086568&amp;group_id=121032&lt;/a&gt;&lt;br&gt;&lt;br&gt;There hasn't been any action as far as I can tell. &amp;nbsp;But maybe you'll
&lt;br&gt;have more luck if you do a new try now.
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26716328&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26716328.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26715229</id>
	<title>Re: Targeted Daemons/Apps- Fedora 12</title>
	<published>2009-12-09T10:34:14Z</published>
	<updated>2009-12-09T10:34:14Z</updated>
	<author>
		<name>Daniel J Walsh</name>
	</author>
	<content type="html">On 12/09/2009 07:06 AM, Jorge Fábregas wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thanks Dominick for the nice explanation. &amp;nbsp;Ok, now I understand it's not as 
&lt;br&gt;&amp;gt; straightforward as I thought. &amp;nbsp;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I originally asked because I remember when RHEL4 and RHEL5 came out, among the 
&lt;br&gt;&amp;gt; new features list, &amp;nbsp; was this list of the &amp;quot;targeted daemons&amp;quot;. &amp;nbsp;Now...as I'm 
&lt;br&gt;&amp;gt; considering SELinux for personal/desktop use. (in Fedora) I was wondering 
&lt;br&gt;&amp;gt; which typical apps (of the base install) were protected (like Thunderbird, 
&lt;br&gt;&amp;gt; Firefox, etc...).
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Again, thanks for pointing me to the right direction.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; All the best,
&lt;br&gt;&amp;gt; Jorge
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26715229&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;You can see all the types associate with processes by executing
&lt;br&gt;&lt;br&gt;seinfo -adomain -x | wc -l
&lt;br&gt;506
&lt;br&gt;&lt;br&gt;Permissive domains
&lt;br&gt;# seinfo --permissive| wc -l
&lt;br&gt;32
&lt;br&gt;&lt;br&gt;Unconfined domains
&lt;br&gt;&lt;br&gt;# seinfo -aunconfined_domain_type -x | wc -l
&lt;br&gt;51
&lt;br&gt;&lt;br&gt;Unconfined domains with unconfined pp file disabled
&lt;br&gt;#semodule -d unconfined
&lt;br&gt;# seinfo -aunconfined_domain_type -x | wc -l
&lt;br&gt;16
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26715229&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Targeted-Daemons-Apps--Fedora-12-tp26693116p26715229.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26709206</id>
	<title>Re: Targeted Daemons/Apps- Fedora 12</title>
	<published>2009-12-09T04:06:15Z</published>
	<updated>2009-12-09T04:06:15Z</updated>
	<author>
		<name>Jorge Fábregas-3</name>
	</author>
	<content type="html">Thanks Dominick for the nice explanation. &amp;nbsp;Ok, now I understand it's not as 
&lt;br&gt;straightforward as I thought. &amp;nbsp;
&lt;br&gt;&lt;br&gt;I originally asked because I remember when RHEL4 and RHEL5 came out, among the 
&lt;br&gt;new features list, &amp;nbsp; was this list of the &amp;quot;targeted daemons&amp;quot;. &amp;nbsp;Now...as I'm 
&lt;br&gt;considering SELinux for personal/desktop use. (in Fedora) I was wondering 
&lt;br&gt;which typical apps (of the base install) were protected (like Thunderbird, 
&lt;br&gt;Firefox, etc...).
&lt;br&gt;&lt;br&gt;Again, thanks for pointing me to the right direction.
&lt;br&gt;&lt;br&gt;All the best,
&lt;br&gt;Jorge
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26709206&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Targeted-Daemons-Apps--Fedora-12-tp26693116p26709206.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26701866</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T13:52:44Z</published>
	<updated>2009-12-08T13:52:44Z</updated>
	<author>
		<name>David P. Quigley</name>
	</author>
	<content type="html">On Tue, 2009-12-08 at 21:37 +0000, Arthur Dent wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Tue, 2009-12-08 at 22:24 +0100, Dominick Grift wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Your myfail2ban.te file should look like this:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; policy_module(myfail2ban, 11.2.1)
&lt;br&gt;&amp;gt; &amp;gt; optional_policy(`
&lt;br&gt;&amp;gt; &amp;gt; gen_require(`
&lt;br&gt;&amp;gt; &amp;gt; attribute domain;
&lt;br&gt;&amp;gt; &amp;gt; type fail2ban_t;
&lt;br&gt;&amp;gt; &amp;gt; ')
&lt;br&gt;&amp;gt; &amp;gt; dontaudit domain fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&amp;gt; &amp;gt; ')
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; That did it - Thanks!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; A leaked file descriptor is a programming error it is where the programmer forgot to close a file descriptor (bug in fail2ban)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; How can I explain this to the f2b developers so that it can be fixed?
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;So I have copied a small section from Dan Walsh's blog. Its a bit more
&lt;br&gt;than forgetting to close a file descriptor. The problem is that by
&lt;br&gt;default on exec the child process will inherit all file descriptors from
&lt;br&gt;the parent except ones that are closed before exec or marked close on
&lt;br&gt;exec with the fcntl listed below.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; One of the interesting things about SELinux is its use to
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; discover bugs in other code. When I first started working with
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; SELinux a few years ago, we started discovering a whole bunch of
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; domains wanting to read and write system_u:object_r:initctl_t
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; file. This is the context of the /dev/initctl device. After
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; investigating for a while we found out something in the boot
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; process was leaking an open file descriptor to /dev/initctl.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This open file descriptor would allow a compromised application
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; to change the run level of the system. Of course all of these
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AVC messages were being reported as bugs in SELinux, but really
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; they were a serious bug in the boot process. Investigating this
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; problem further I found that the default behavior of all file
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; descriptors is to have them inherited over the fork/exec. You
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; have to execute fcntl(fd, F_SETFD, FD_CLOEXEC); on all file
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; descriptors that you do not want to be leaked. Needless to say,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; lots of programmers forget this and leaked file descriptors are
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; quite common.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dan Walsh
&lt;br&gt;&lt;br&gt;&amp;gt; Thanks - yet again!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Mark
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701866&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&lt;br&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701866&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26701866.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26701260</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T13:37:59Z</published>
	<updated>2009-12-08T13:37:59Z</updated>
	<author>
		<name>Arthur Dent-6</name>
	</author>
	<content type="html">On Tue, 2009-12-08 at 22:24 +0100, Dominick Grift wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Your myfail2ban.te file should look like this:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; policy_module(myfail2ban, 11.2.1)
&lt;br&gt;&amp;gt; optional_policy(`
&lt;br&gt;&amp;gt; gen_require(`
&lt;br&gt;&amp;gt; attribute domain;
&lt;br&gt;&amp;gt; type fail2ban_t;
&lt;br&gt;&amp;gt; ')
&lt;br&gt;&amp;gt; dontaudit domain fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&amp;gt; ')
&lt;/div&gt;&lt;/div&gt;That did it - Thanks!
&lt;br&gt;&lt;br&gt;&amp;gt; A leaked file descriptor is a programming error it is where the programmer forgot to close a file descriptor (bug in fail2ban)
&lt;br&gt;&lt;br&gt;How can I explain this to the f2b developers so that it can be fixed?
&lt;br&gt;&lt;br&gt;Thanks - yet again!
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701260&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26701260/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26701260.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26701038</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T13:24:39Z</published>
	<updated>2009-12-08T13:24:39Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Tue, Dec 08, 2009 at 09:15:48PM +0000, Arthur Dent wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Tue, 2009-12-08 at 21:57 +0100, Dominick Grift wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; So what do you think?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Am I on the right track?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Yes &amp;quot;allow system_mail_t fail2ban_t:unix_stream_socket { read write };&amp;quot;, signals a leaked file descriptor on fail2ban. This issue is known. You can ignore those avc denials and/or silence them:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; What exactly *is* a &amp;quot;leaked file descriptor&amp;quot;?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;policy_module(myfail2ban, 1.0.0)&amp;quot; &amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;attribute domain;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;type fail2ban_t;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;dontaudit domain fail2ban_t:unix_stream_socket { read write };&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; &amp;gt; echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; OK - Thanks for this. It's not the way I'm used to generating local
&lt;br&gt;&amp;gt; policies and I think there may be an error? Once all the lines are
&lt;br&gt;&amp;gt; echo'd into myfail2ban.te this is what I get:
&lt;br&gt;&amp;gt; # cat myfail2ban.te
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; policy_module(myfail2ban, 11.2.1)
&lt;br&gt;&amp;gt; optional_policy(`
&lt;br&gt;&amp;gt; gen_require(`
&lt;br&gt;&amp;gt; attribute domain;
&lt;br&gt;&amp;gt; type fail2ban_t;
&lt;br&gt;&amp;gt; \')
&lt;br&gt;&amp;gt; dontaudit domain fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&amp;gt; \')
&lt;/div&gt;&lt;/div&gt;Your myfail2ban.te file should look like this:
&lt;br&gt;&lt;br&gt;policy_module(myfail2ban, 11.2.1)
&lt;br&gt;optional_policy(`
&lt;br&gt;gen_require(`
&lt;br&gt;attribute domain;
&lt;br&gt;type fail2ban_t;
&lt;br&gt;')
&lt;br&gt;dontaudit domain fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;')
&lt;br&gt;&lt;br&gt;A leaked file descriptor is a programming error it is where the programmer forgot to close a file descriptor (bug in fail2ban)
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Which won't compile: 
&lt;br&gt;&amp;gt; &amp;gt; make -f /usr/share/selinux/devel/Makefile myfail2ban.pp
&lt;br&gt;&amp;gt; &amp;gt; sudo semodule -i myfail2ban.pp
&lt;br&gt;&amp;gt; Gives:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; # make -f /usr/share/selinux/devel/Makefile myfail2ban.pp
&lt;br&gt;&amp;gt; Compiling targeted myfail2ban module
&lt;br&gt;&amp;gt; /usr/bin/checkmodule: &amp;nbsp;loading policy configuration from
&lt;br&gt;&amp;gt; tmp/myfail2ban.tmp
&lt;br&gt;&amp;gt; myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;&amp;gt; 3204:
&lt;br&gt;&amp;gt; \
&lt;br&gt;&amp;gt; #line 2
&lt;br&gt;&amp;gt; myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;&amp;gt; 3214:
&lt;br&gt;&amp;gt; \
&lt;br&gt;&amp;gt; #line 2
&lt;br&gt;&amp;gt; myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;&amp;gt; 3204:
&lt;br&gt;&amp;gt; \
&lt;br&gt;&amp;gt; #line 2
&lt;br&gt;&amp;gt; myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;&amp;gt; 3214:
&lt;br&gt;&amp;gt; \
&lt;br&gt;&amp;gt; #line 2
&lt;br&gt;&amp;gt; /usr/bin/checkmodule: &amp;nbsp;policy configuration loaded
&lt;br&gt;&amp;gt; /usr/bin/checkmodule: &amp;nbsp;writing binary representation (version 10) to
&lt;br&gt;&amp;gt; tmp/myfail2ban.mod
&lt;br&gt;&amp;gt; Creating targeted myfail2ban.pp policy package
&lt;br&gt;&amp;gt; rm tmp/myfail2ban.mod.fc tmp/myfail2ban.mod
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm not exactly sure what you had in mind otherwise I would edit it to
&lt;br&gt;&amp;gt; work...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; But thanks again. I do appreciate your help!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Mark
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701038&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701038&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26701038/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26701038.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26700900</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T13:15:48Z</published>
	<updated>2009-12-08T13:15:48Z</updated>
	<author>
		<name>Arthur Dent-6</name>
	</author>
	<content type="html">On Tue, 2009-12-08 at 21:57 +0100, Dominick Grift wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; So what do you think?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Am I on the right track?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Yes &amp;quot;allow system_mail_t fail2ban_t:unix_stream_socket { read write };&amp;quot;, signals a leaked file descriptor on fail2ban. This issue is known. You can ignore those avc denials and/or silence them:
&lt;br&gt;&lt;br&gt;What exactly *is* a &amp;quot;leaked file descriptor&amp;quot;?
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt; echo &amp;quot;policy_module(myfail2ban, 1.0.0)&amp;quot; &amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;attribute domain;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;type fail2ban_t;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;dontaudit domain fail2ban_t:unix_stream_socket { read write };&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&amp;gt; echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&lt;br&gt;OK - Thanks for this. It's not the way I'm used to generating local
&lt;br&gt;policies and I think there may be an error? Once all the lines are
&lt;br&gt;echo'd into myfail2ban.te this is what I get:
&lt;br&gt;# cat myfail2ban.te
&lt;br&gt;&lt;br&gt;policy_module(myfail2ban, 11.2.1)
&lt;br&gt;optional_policy(`
&lt;br&gt;gen_require(`
&lt;br&gt;attribute domain;
&lt;br&gt;type fail2ban_t;
&lt;br&gt;\')
&lt;br&gt;dontaudit domain fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;\')
&lt;br&gt;&lt;br&gt;Which won't compile: 
&lt;br&gt;&amp;gt; make -f /usr/share/selinux/devel/Makefile myfail2ban.pp
&lt;br&gt;&amp;gt; sudo semodule -i myfail2ban.pp
&lt;br&gt;Gives:
&lt;br&gt;&lt;br&gt;# make -f /usr/share/selinux/devel/Makefile myfail2ban.pp
&lt;br&gt;Compiling targeted myfail2ban module
&lt;br&gt;/usr/bin/checkmodule: &amp;nbsp;loading policy configuration from
&lt;br&gt;tmp/myfail2ban.tmp
&lt;br&gt;myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;3204:
&lt;br&gt;\
&lt;br&gt;#line 2
&lt;br&gt;myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;3214:
&lt;br&gt;\
&lt;br&gt;#line 2
&lt;br&gt;myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;3204:
&lt;br&gt;\
&lt;br&gt;#line 2
&lt;br&gt;myfail2ban.te&amp;quot;:2:WARNING 'unrecognized character' at token '\' on line
&lt;br&gt;3214:
&lt;br&gt;\
&lt;br&gt;#line 2
&lt;br&gt;/usr/bin/checkmodule: &amp;nbsp;policy configuration loaded
&lt;br&gt;/usr/bin/checkmodule: &amp;nbsp;writing binary representation (version 10) to
&lt;br&gt;tmp/myfail2ban.mod
&lt;br&gt;Creating targeted myfail2ban.pp policy package
&lt;br&gt;rm tmp/myfail2ban.mod.fc tmp/myfail2ban.mod
&lt;br&gt;&lt;br&gt;&lt;br&gt;I'm not exactly sure what you had in mind otherwise I would edit it to
&lt;br&gt;work...
&lt;br&gt;&lt;br&gt;&lt;br&gt;But thanks again. I do appreciate your help!
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26700900&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26700900/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26700900.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26700627</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T12:57:29Z</published>
	<updated>2009-12-08T12:57:29Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Tue, Dec 08, 2009 at 08:43:32PM +0000, Arthur Dent wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Mon, 2009-12-07 at 23:51 +0100, Dominick Grift wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; [Snip]
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; # matchpathcon /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; /usr/bin/fail2ban-server	system_u:object_r:fail2ban_exec_t:s0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; Is that what you would expect to see?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; yes, now the question is, is the path labeled the way it should be:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; # ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -rwxr-xr-x. root root unconfined_u:object_r:bin_t:s0 &amp;nbsp; /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Hmmmm...
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; # restorecon -v /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; restorecon reset /usr/bin/fail2ban-server context unconfined_u:object_r:bin_t:s0-&amp;gt;system_u:object_r:fail2ban_exec_t:s0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; # ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; -rwxr-xr-x. root root system_u:object_r:fail2ban_exec_t:s0 /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Ahhh...
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Is that more like it?
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Yes that should get you atleast a little closer. I am wondering what else may be mislabeled on your system.
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; maybe a relabel/fixfiles restore is in order...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Yes. Good advice.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; As it happens there was a new selinux policy available today (using yum
&lt;br&gt;&amp;gt; update):
&lt;br&gt;&amp;gt; # rpm -q selinux-policy selinux-policy-targeted
&lt;br&gt;&amp;gt; selinux-policy-3.6.12-91.fc11.noarch
&lt;br&gt;&amp;gt; selinux-policy-targeted-3.6.12-91.fc11.noarch
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I removed two of my local policies (log rotation and fail2ban) and put
&lt;br&gt;&amp;gt; selinux into permissive mode.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Having updated I did a &amp;quot;touch /.autorelabel; reboot&amp;quot;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Following your 7 point plan I believe I am now at stage 6?
&lt;br&gt;&amp;gt; {
&lt;br&gt;&amp;gt; 1) I believe there is a type created for the process? (fail2ban_exec)
&lt;br&gt;&amp;gt; 2) I believe there is a type for the executable file (fail2ban_exec)
&lt;br&gt;&amp;gt; 3) declare the two types init_daemon_domain(). (Not sure about this)
&lt;br&gt;&amp;gt; 4) The executable file is labelled with the type fail2ban_exec
&lt;br&gt;&amp;gt; 5) I have started the service (in permissive mode).
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I got 5 AVCs. 2 on startup and 3 when fail2ban actually hit on a rule.
&lt;br&gt;&amp;gt; (Copies of the AVCs below)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; So - point 6: Using audit2allow I get this:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; =================8&amp;lt;============================================
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; module myfail2ban 11.2.1;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; require {
&lt;br&gt;&amp;gt; 	type iptables_t;
&lt;br&gt;&amp;gt; 	type system_mail_t;
&lt;br&gt;&amp;gt; 	type fail2ban_t;
&lt;br&gt;&amp;gt; 	class unix_stream_socket { read write };
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= iptables_t ==============
&lt;br&gt;&amp;gt; allow iptables_t fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #============= system_mail_t ==============
&lt;br&gt;&amp;gt; allow system_mail_t fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; =================8&amp;lt;============================================
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; So what do you think?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Am I on the right track?
&lt;/div&gt;&lt;/div&gt;Yes &amp;quot;allow system_mail_t fail2ban_t:unix_stream_socket { read write };&amp;quot;, signals a leaked file descriptor on fail2ban. This issue is known. You can ignore those avc denials and/or silence them:
&lt;br&gt;&lt;br&gt;echo &amp;quot;policy_module(myfail2ban, 1.0.0)&amp;quot; &amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;optional_policy(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;gen_require(\`&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;attribute domain;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;type fail2ban_t;&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;dontaudit domain fail2ban_t:unix_stream_socket { read write };&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;echo &amp;quot;\')&amp;quot; &amp;gt;&amp;gt; myfail2ban.te;
&lt;br&gt;&lt;br&gt;make -f /usr/share/selinux/devel/Makefile myfail2ban.pp
&lt;br&gt;sudo semodule -i myfail2ban.pp
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks again for all your help.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Mark
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; AVCs (I think a couple may be duplicates - I'm running in permissive
&lt;br&gt;&amp;gt; mode):
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=AVC msg=audit(1260298720.4:21): avc: denied { read write } for pid=1907 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=SYSCALL msg=audit(1260298720.4:21): arch=40000003 syscall=11 success=yes exit=0 a0=8a1a250 a1=8a1a460 a2=8a19738 a3=8a1a460 items=0 ppid=1906 pid=1907 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=AVC msg=audit(1260298720.169:22): avc: denied { read write } for pid=1921 comm=&amp;quot;sendmail&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=SYSCALL msg=audit(1260298720.169:22): arch=40000003 syscall=11 success=yes exit=0 a0=85867d0 a1=8587798 a2=8587670 a3=8587798 items=0 ppid=1919 pid=1921 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=51 sgid=51 fsgid=51 tty=(none) ses=4294967295 comm=&amp;quot;sendmail&amp;quot; exe=&amp;quot;/usr/sbin/sendmail.sendmail&amp;quot; subj=system_u:system_r:system_mail_t:s0 key=(null) 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=AVC msg=audit(1260301404.622:121): avc: denied { read write } for pid=2799 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=SYSCALL msg=audit(1260301404.622:121): arch=40000003 syscall=11 success=yes exit=0 a0=88b13e0 a1=88b1618 a2=88b06f8 a3=88b1618 items=0 ppid=2798 pid=2799 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=AVC msg=audit(1260301405.169:122): avc: denied { read write } for pid=2804 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=SYSCALL msg=audit(1260301405.169:122): arch=40000003 syscall=11 success=yes exit=0 a0=96e3418 a1=96e3718 a2=96e2700 a3=96e3718 items=0 ppid=1901 pid=2804 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Raw Audit Messages :
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=AVC msg=audit(1260301405.212:123): avc: denied { read write } for pid=2811 comm=&amp;quot;sendmail&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;&amp;gt; node=troodos.org.uk type=SYSCALL msg=audit(1260301405.212:123): arch=40000003 syscall=11 success=yes exit=0 a0=a119518 a1=a119a48 a2=a119750 a3=a119a48 items=0 ppid=2807 pid=2811 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=51 sgid=51 fsgid=51 tty=(none) ses=4294967295 comm=&amp;quot;sendmail&amp;quot; exe=&amp;quot;/usr/sbin/sendmail.sendmail&amp;quot; subj=system_u:system_r:system_mail_t:s0 key=(null) 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26700627&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26700627&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26700627/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26700627.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26700392</id>
	<title>Re: Selinux &amp; Fail2Ban</title>
	<published>2009-12-08T12:43:32Z</published>
	<updated>2009-12-08T12:43:32Z</updated>
	<author>
		<name>Arthur Dent-6</name>
	</author>
	<content type="html">On Mon, 2009-12-07 at 23:51 +0100, Dominick Grift wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; &amp;gt; [Snip]
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; # matchpathcon /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; /usr/bin/fail2ban-server	system_u:object_r:fail2ban_exec_t:s0
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; Is that what you would expect to see?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; yes, now the question is, is the path labeled the way it should be:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; # ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; -rwxr-xr-x. root root unconfined_u:object_r:bin_t:s0 &amp;nbsp; /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Hmmmm...
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; # restorecon -v /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; restorecon reset /usr/bin/fail2ban-server context unconfined_u:object_r:bin_t:s0-&amp;gt;system_u:object_r:fail2ban_exec_t:s0
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; # ls -alZ /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; -rwxr-xr-x. root root system_u:object_r:fail2ban_exec_t:s0 /usr/bin/fail2ban-server
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Ahhh...
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; Is that more like it?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Yes that should get you atleast a little closer. I am wondering what else may be mislabeled on your system.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; maybe a relabel/fixfiles restore is in order...
&lt;/div&gt;&lt;/div&gt;Yes. Good advice.
&lt;br&gt;&lt;br&gt;As it happens there was a new selinux policy available today (using yum
&lt;br&gt;update):
&lt;br&gt;# rpm -q selinux-policy selinux-policy-targeted
&lt;br&gt;selinux-policy-3.6.12-91.fc11.noarch
&lt;br&gt;selinux-policy-targeted-3.6.12-91.fc11.noarch
&lt;br&gt;&lt;br&gt;&lt;br&gt;I removed two of my local policies (log rotation and fail2ban) and put
&lt;br&gt;selinux into permissive mode.
&lt;br&gt;&lt;br&gt;Having updated I did a &amp;quot;touch /.autorelabel; reboot&amp;quot;
&lt;br&gt;&lt;br&gt;Following your 7 point plan I believe I am now at stage 6?
&lt;br&gt;{
&lt;br&gt;1) I believe there is a type created for the process? (fail2ban_exec)
&lt;br&gt;2) I believe there is a type for the executable file (fail2ban_exec)
&lt;br&gt;3) declare the two types init_daemon_domain(). (Not sure about this)
&lt;br&gt;4) The executable file is labelled with the type fail2ban_exec
&lt;br&gt;5) I have started the service (in permissive mode).
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;I got 5 AVCs. 2 on startup and 3 when fail2ban actually hit on a rule.
&lt;br&gt;(Copies of the AVCs below)
&lt;br&gt;&lt;br&gt;So - point 6: Using audit2allow I get this:
&lt;br&gt;&lt;br&gt;=================8&amp;lt;============================================
&lt;br&gt;&lt;br&gt;module myfail2ban 11.2.1;
&lt;br&gt;&lt;br&gt;require {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type iptables_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type system_mail_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; type fail2ban_t;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class unix_stream_socket { read write };
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;#============= iptables_t ==============
&lt;br&gt;allow iptables_t fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&lt;br&gt;#============= system_mail_t ==============
&lt;br&gt;allow system_mail_t fail2ban_t:unix_stream_socket { read write };
&lt;br&gt;&lt;br&gt;=================8&amp;lt;============================================
&lt;br&gt;&lt;br&gt;So what do you think?
&lt;br&gt;&lt;br&gt;Am I on the right track?
&lt;br&gt;&lt;br&gt;Thanks again for all your help.
&lt;br&gt;&lt;br&gt;Mark
&lt;br&gt;&lt;br&gt;&lt;br&gt;AVCs (I think a couple may be duplicates - I'm running in permissive
&lt;br&gt;mode):
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260298720.4:21): avc: denied { read write } for pid=1907 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260298720.4:21): arch=40000003 syscall=11 success=yes exit=0 a0=8a1a250 a1=8a1a460 a2=8a19738 a3=8a1a460 items=0 ppid=1906 pid=1907 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260298720.169:22): avc: denied { read write } for pid=1921 comm=&amp;quot;sendmail&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260298720.169:22): arch=40000003 syscall=11 success=yes exit=0 a0=85867d0 a1=8587798 a2=8587670 a3=8587798 items=0 ppid=1919 pid=1921 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=51 sgid=51 fsgid=51 tty=(none) ses=4294967295 comm=&amp;quot;sendmail&amp;quot; exe=&amp;quot;/usr/sbin/sendmail.sendmail&amp;quot; subj=system_u:system_r:system_mail_t:s0 key=(null) 
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260301404.622:121): avc: denied { read write } for pid=2799 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260301404.622:121): arch=40000003 syscall=11 success=yes exit=0 a0=88b13e0 a1=88b1618 a2=88b06f8 a3=88b1618 items=0 ppid=2798 pid=2799 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260301405.169:122): avc: denied { read write } for pid=2804 comm=&amp;quot;iptables&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:iptables_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260301405.169:122): arch=40000003 syscall=11 success=yes exit=0 a0=96e3418 a1=96e3718 a2=96e2700 a3=96e3718 items=0 ppid=1901 pid=2804 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=&amp;quot;iptables&amp;quot; exe=&amp;quot;/sbin/iptables&amp;quot; subj=system_u:system_r:iptables_t:s0 key=(null) 
&lt;br&gt;&lt;br&gt;Raw Audit Messages :
&lt;br&gt;&lt;br&gt;node=troodos.org.uk type=AVC msg=audit(1260301405.212:123): avc: denied { read write } for pid=2811 comm=&amp;quot;sendmail&amp;quot; path=&amp;quot;socket:[16217]&amp;quot; dev=sockfs ino=16217 scontext=system_u:system_r:system_mail_t:s0 tcontext=system_u:system_r:fail2ban_t:s0 tclass=unix_stream_socket 
&lt;br&gt;node=troodos.org.uk type=SYSCALL msg=audit(1260301405.212:123): arch=40000003 syscall=11 success=yes exit=0 a0=a119518 a1=a119a48 a2=a119750 a3=a119a48 items=0 ppid=2807 pid=2811 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=51 sgid=51 fsgid=51 tty=(none) ses=4294967295 comm=&amp;quot;sendmail&amp;quot; exe=&amp;quot;/usr/sbin/sendmail.sendmail&amp;quot; subj=system_u:system_r:system_mail_t:s0 key=(null) 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26700392&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (204 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26700392/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Logrotate-frustration-tp26663334p26700392.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26698857</id>
	<title>Re: Combining modules?</title>
	<published>2009-12-08T10:57:10Z</published>
	<updated>2009-12-08T10:57:10Z</updated>
	<author>
		<name>Dominick Grift</name>
	</author>
	<content type="html">On Tue, Dec 08, 2009 at 10:41:51AM -0800, John Oliver wrote:
&lt;br&gt;&amp;gt; I don't know if there's a better way to do this, but I'm trying to get
&lt;br&gt;&amp;gt; nagios working with selinux (CentOS 5.4 Final) &amp;nbsp;I try to run it, get an
&lt;br&gt;&amp;gt; error, create a policy module, install it, and return to step one. &amp;nbsp;It's
&lt;br&gt;&amp;gt; getting pretty ridiculous:
&lt;br&gt;&lt;br&gt;Yes common issue with developing policy. What developers usually do it develop policy in permissive mode or in fedora11 and up using permissive domains. These methods allow you to accumulate all or atleast most avc denials in one runs. This is because permissive mode/domains allow the access but log &amp;quot;would be denials&amp;quot;. So the process usually works but youll still get to see what SELinux would have denied.
&lt;br&gt;&lt;br&gt;But apart from that. You can also develop policy in enforcing mode. Although since selinux actually denies every permission the process cannot proceed. So youll write a rule, reload modified policy, appends the next rule, reload and so forth an so forth.
&lt;br&gt;&lt;br&gt;An easier way to do that is to just modify your source policy (the .te, .if and .fc files), rebuild the binary policy and install it again. That will overwrite the installed policy.
&lt;br&gt;&lt;br&gt;echo &amp;quot;policy_module(example, 1.0.0)&amp;quot; &amp;gt; example.te;
&lt;br&gt;make -f /usr/share/selinux/devel/Makefile example.pp
&lt;br&gt;sudo semodule -i example.pp
&lt;br&gt;( .. later you figure out more policy is required .. )
&lt;br&gt;( .. appending some stuff to existing source policy example.te file .. )
&lt;br&gt;echo &amp;quot;type example_t;&amp;quot; &amp;gt;&amp;gt; example.te;
&lt;br&gt;echo &amp;quot;type example_exec_t;&amp;quot; &amp;gt;&amp;gt; example.te;
&lt;br&gt;echo &amp;quot;init_daemon_domain(example_t, example_exec_t)&amp;quot; &amp;gt;&amp;gt; example.te;
&lt;br&gt;( .. building a binary module again this time from modified source policy example.te file .. )
&lt;br&gt;make -f /usr/share/selinux/devel/Makefile example.pp
&lt;br&gt;( .. installing modified example.pp binary module *again*, whichif policy version is the same, overwrites the existing installed example.pp)
&lt;br&gt;&lt;br&gt;That way you will end up with a single module with all your mods for a particular domain.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; [joliver@mda-services4 ~]$ sudo /usr/sbin/semodule -l | grep nagios
&lt;br&gt;&amp;gt; nagios &amp;nbsp;1.1.0
&lt;br&gt;&amp;gt; nagios10 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.0
&lt;br&gt;&amp;gt; nagios2 1.0
&lt;br&gt;&amp;gt; nagios3 1.0
&lt;br&gt;&amp;gt; nagios4 1.0
&lt;br&gt;&amp;gt; nagios5 1.0
&lt;br&gt;&amp;gt; nagios6 1.0
&lt;br&gt;&amp;gt; nagios7 1.0
&lt;br&gt;&amp;gt; nagios8 1.0
&lt;br&gt;&amp;gt; nagios9 1.0
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; When I finally discover all of the problems... is there a way to dump
&lt;br&gt;&amp;gt; all of those modules into one? &amp;nbsp;Both for my sanity, and so that I can
&lt;br&gt;&amp;gt; maybe submit that module to CentOS so the next poor SOB who tries to do
&lt;br&gt;&amp;gt; this doesn't have to reinvent the wheel?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Or is there another, better, way to find all of the various rules that
&lt;br&gt;&amp;gt; are needed in one fell swoop?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; ***********************************************************************
&lt;br&gt;&amp;gt; * John Oliver &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.john-oliver.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.john-oliver.net/&lt;/a&gt;&amp;nbsp;*
&lt;br&gt;&amp;gt; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; *
&lt;br&gt;&amp;gt; ***********************************************************************
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; fedora-selinux-list mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26698857&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26698857&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26698857/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Combining-modules--tp26698631p26698857.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26698692</id>
	<title>Re: Combining modules?</title>
	<published>2009-12-08T10:46:10Z</published>
	<updated>2009-12-08T10:46:10Z</updated>
	<author>
		<name>Joshua Roys-2</name>
	</author>
	<content type="html">On 12/08/2009 01:41 PM, John Oliver wrote:
&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I don't know if there's a better way to do this, but I'm trying to get
&lt;br&gt;&amp;gt; nagios working with selinux (CentOS 5.4 Final) &amp;nbsp;I try to run it, get an
&lt;br&gt;&amp;gt; error, create a policy module, install it, and return to step one. &amp;nbsp;It's
&lt;br&gt;&amp;gt; getting pretty ridiculous:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [joliver@mda-services4 ~]$ sudo /usr/sbin/semodule -l | grep nagios
&lt;br&gt;&amp;gt; nagios &amp;nbsp;1.1.0
&lt;br&gt;&amp;gt; nagios10 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.0
&lt;br&gt;&amp;gt; nagios2 1.0
&lt;br&gt;&amp;gt; nagios3 1.0
&lt;br&gt;&amp;gt; nagios4 1.0
&lt;br&gt;&amp;gt; nagios5 1.0
&lt;br&gt;&amp;gt; nagios6 1.0
&lt;br&gt;&amp;gt; nagios7 1.0
&lt;br&gt;&amp;gt; nagios8 1.0
&lt;br&gt;&amp;gt; nagios9 1.0
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; When I finally discover all of the problems... is there a way to dump
&lt;br&gt;&amp;gt; all of those modules into one? &amp;nbsp;Both for my sanity, and so that I can
&lt;br&gt;&amp;gt; maybe submit that module to CentOS so the next poor SOB who tries to do
&lt;br&gt;&amp;gt; this doesn't have to reinvent the wheel?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Or is there another, better, way to find all of the various rules that
&lt;br&gt;&amp;gt; are needed in one fell swoop?
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;/div&gt;Instead of making a new file, you can just edit the old files, bump the 
&lt;br&gt;version, and instead of semodule -i, use semodule -u (update).
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;--
&lt;br&gt;fedora-selinux-list mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26698692&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;fedora-selinux-list@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.redhat.com/mailman/listinfo/fedora-selinux-list&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (3K) &lt;a href=&quot;http://old.nabble.com/attachment/26698692/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Combining-modules--tp26698631p26698692.html" />
</entry>

</feed>
