selinux using all my cpu
Hi,
I've been using Fedora 10 i686 for a few months. In the past week or so, selinux has started a process at boot time which eats up a lot of my resources. For five minutes or so, setroubleshootd uses 50-70% of CPU time, and after that /usr/bin/sealer takes over and uses 70-90% of CPU until I kill it. I don't get any SELinux alerts in the Gnome notification area when this is going on, or any other visible indication of what might be happening. grepping /var/log/messages forsetroubleshoot reveals the following messages for today: Code:
Feb 1 11:16:20 mer39 setroubleshoot: [rpc.ERROR] attempt to open server connection failed: No such file or directory Only other thing I can see that might be relevant is that during the first few mins when setroubleshootd is the cpu hog, mount.ntfs is also using about 20% of cpu, and this dies down when sealer takes over. Something to do with one of my ntfs partitions maybe? Here are the ntfs-related lines from fstab: Code:
/dev/sda2 /mnt/win ntfs ro,noauto,users,exec 0 2 |
Quote:
|
Quote:
Quote:
I'm not sure exactly what gets put in audit.log or how to read it; I noticed it logged uses of sudo, so below is the output of sudo grep -v sudo /var/log/audit/audit.log | tail Code:
type=AVC msg=audit(1233575326.192:33): avc: denied { read } for pid=7802 comm="logrotate" name="openSauce" dev=sda1 ino=1860482 scontext=system_u:system_r:logrotate_t:s0 tcontext=system_u:object_r:user_home_dir_t:s0 tclass=dir Quote:
|
Quote:
Quote:
|
I seem to have fixed the original problem: it turned out I hadn't actually relabelled the log file in root's home dir, now that I've done this, sealert doesn't hog the cpu, and the file's in my home dir are being rotated.
I'm not sure what to do about the broken pipe error, /var/run/setroubleshoot/setroubleshoot_server has correct permissions and context, but it doesn't seem to be causing any issues with day-to-day usage, so I might just leave it for now, unless you think it could be a security risk? Thanks for your time |
Quote:
Quote:
|
All times are GMT -5. The time now is 05:11 PM. |