--- MASTER/testing/pluto/ikev2-labeled-ipsec-03-multi-acquires-permissive/east.console.txt +++ OUTPUT/testing/pluto/ikev2-labeled-ipsec-03-multi-acquires-permissive/east.console.txt @@ -117,4 +117,54 @@ Certificate Nickname Trust Attributes SSL,S/MIME,JAR/XPI east # + >>>>>>>>>> post-mortem >>>>>>>>>>../../guestbin/post-mortem.sh + PPID PID PGID SID TTY TPGID STAT UID TIME COMMAND + 1 808 808 808 ? -1 Ssl 0 0:00 PATH/libexec/ipsec/pluto --leak-detective --config /etc/ipsec.conf --nofork +: +: checking shutting down pluto +: +ipsec whack --shutdown +pidof pluto +PASS: shutting down pluto +: +: checking core files +: +PASS: core files +: +: checking memory leaks +: +PASS: memory leaks +: +: checking reference leaks +: +PASS: reference leaks +: +: checking xfrm errors +: +ERROR: east: XfrmOutNoStates 1 +IGNORE: xfrm errors +: +: checking state/policy entries +: +PASS: state/policy entries +: +: checking selinux audit records +: +type=AVC msg=audit(1652549686.957:188): avc: denied { setcontext } for pid=808 comm="pluto" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tclass=association permissive=1 +FAIL: selinux audit records +saving rules in OUTPUT/post-mortem.east.audit2allow.rules +require { + type sshd_t; + type unconfined_service_t; + class association setcontext; +} +#============= unconfined_service_t ============== +allow unconfined_service_t sshd_t:association setcontext; +: +: unload any selinux modules +: +Unloading ipsecspd +semodule -r ipsecspd +libsemanage.semanage_direct_remove_key: Removing last ipsecspd module (no other ipsecspd module exists at another priority). +east #