| Summary: | selinux prevents use of gnome-sound-recorder | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | bodhi.zazen <bodhi.zazen> |
| Component: | selinux-policy-targeted | Assignee: | Miroslav Grepl <mgrepl> |
| Status: | CLOSED NOTABUG | QA Contact: | Ben Levenson <benl> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 15 | CC: | bodhi.zazen, dwalsh |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2011-06-10 03:04:51 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
bodhi.zazen
2011-06-07 04:14:10 UTC
Try to run # setsebool user_tcp_server on and re-test it. Also # ps -eZ |grep audit Thank you , but that did not help root@fedora:~#getsebool -a | grep user_tcp user_tcp_server --> on root@fedora:~#ps -eZ | grep audit system_u:system_r:kernel_t:s0 365 ? 00:00:00 kauditd system_u:system_r:auditd_t:s0 840 ? 00:00:00 auditd OK, setting that Boolean did fix it, I had to reboot for it to take effect. One last question if I may, how was I to know to set that particular boolean without a denial / selinux alert / AVC in the logs ? You would not know. You would have to understand that confined users are not allowed to listen on any ports out of the box. And then know there was a boolean that allowed this access. If you ran that avc through audit2allow it would have told you of the existance of the boolean, or setroubleshoot should have told you also, |