selinux.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* SELinux logging problem
@ 2018-12-04 16:03 BMK
  2018-12-04 16:38 ` Stephen Smalley
  0 siblings, 1 reply; 10+ messages in thread
From: BMK @ 2018-12-04 16:03 UTC (permalink / raw)
  To: selinux

Hello,

I am currently struggling with a strange SELinux problem,
for which I am not able to find an answer by reading the documentation
and researching online.

The problem is, that some AVC denial log entries seem to get lost in
permissive mode,
in other words, they are not logged...
I've already deactivated all dont audit rules and I know for sure that
the denial actually occurs, because I can trace it via strace...
Although I can't see a corresponding entry in the audit.log.
By the way, in enforcing mode I can see suddenly the missing denial entry...
If the permissive mode lacks/drops some denials which we can only see
in enforcing mode,
then this would be truly terrible for the policy writers...
Otherwise I am out of ideas, what other things could cause the loss of
SELinux denials...

I hope you can point me to right direction with this matter and
I thank you in advance for your help.

Best regards,
BMK

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2018-12-04 20:06 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-12-04 16:03 SELinux logging problem BMK
2018-12-04 16:38 ` Stephen Smalley
2018-12-04 16:52   ` Stephen Smalley
2018-12-04 18:00     ` BMK
2018-12-04 18:39       ` Stephen Smalley
2018-12-04 19:01         ` BMK
2018-12-04 19:42           ` Stephen Smalley
2018-12-04 19:56             ` BMK
2018-12-04 20:05               ` Stephen Smalley
2018-12-04 20:06                 ` BMK

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).