Skip to content

Instantly share code, notes, and snippets.

@pweil-
Created June 13, 2018 17:59
Show Gist options
  • Save pweil-/61b3b233999d528ce62f737fb9218624 to your computer and use it in GitHub Desktop.
Save pweil-/61b3b233999d528ce62f737fb9218624 to your computer and use it in GitHub Desktop.
[root@ocp-master-30863601-0 0]# ausearch -m avc -ts recent
----
time->Wed Jun 13 16:53:26 2018
type=PROCTITLE msg=audit(1528908806.025:28): proctitle=2F62696E2F62617368002D65002F7573722F6C6F63616C2F62696E2F656E747279706F696E74002F6F70742F6170702D726F6F742F7372632F616E7369626C652E7368
type=SYSCALL msg=audit(1528908806.025:28): arch=c000003e syscall=2 success=no exit=-13 a0=7fda8ed30607 a1=80000 a2=1 a3=7fda8ef364f8 items=0 ppid=25690 pid=25707 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="entrypoint" exe="/usr/bin/bash" subj=system_u:system_r:container_t:s0:c613,c722 key=(null)
type=AVC msg=audit(1528908806.025:28): avc: denied { read open } for pid=25707 comm="entrypoint" path="/etc/ld.so.cache" dev="sdb1" ino=33994991 scontext=system_u:system_r:container_t:s0:c613,c722 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
----
time->Wed Jun 13 16:53:26 2018
type=PROCTITLE msg=audit(1528908806.026:29): proctitle=2F62696E2F62617368002D65002F7573722F6C6F63616C2F62696E2F656E747279706F696E74002F6F70742F6170702D726F6F742F7372632F616E7369626C652E7368
type=SYSCALL msg=audit(1528908806.026:29): arch=c000003e syscall=2 success=no exit=-13 a0=7ffc7a5ba240 a1=80000 a2=7fda8ef36150 a3=0 items=0 ppid=25690 pid=25707 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="entrypoint" exe="/usr/bin/bash" subj=system_u:system_r:container_t:s0:c613,c722 key=(null)
type=AVC msg=audit(1528908806.026:29): avc: denied { read open } for pid=25707 comm="entrypoint" path="/usr/lib64/libtinfo.so.5.9" dev="sdb1" ino=33588045 scontext=system_u:system_r:container_t:s0:c613,c722 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
----
time->Wed Jun 13 16:53:26 2018
type=PROCTITLE msg=audit(1528908806.026:30): proctitle=2F62696E2F62617368002D65002F7573722F6C6F63616C2F62696E2F656E747279706F696E74002F6F70742F6170702D726F6F742F7372632F616E7369626C652E7368
type=SYSCALL msg=audit(1528908806.026:30): arch=c000003e syscall=2 success=no exit=-13 a0=7ffc7a5ba240 a1=80000 a2=7fda8ef36150 a3=0 items=0 ppid=25690 pid=25707 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="entrypoint" exe="/usr/bin/bash" subj=system_u:system_r:container_t:s0:c613,c722 key=(null)
type=AVC msg=audit(1528908806.026:30): avc: denied { read open } for pid=25707 comm="entrypoint" path="/usr/lib64/libtinfo.so.5.9" dev="sdb1" ino=33588045 scontext=system_u:system_r:container_t:s0:c613,c722 tcontext=system_u:object_r:unlabeled_t:s0 tclass=file
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment