Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing gnome-shell from using the 'signull' accesses on a process. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that gnome-shell should be allowed signull access on processes labeled unconfined_service_t by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # grep gnome-shell /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023 Target Context system_u:system_r:unconfined_service_t:s0-s0:c0.c1 023 Target Objects Unknown [ process ] Source gnome-shell Source Path gnome-shell Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.13.1-146.fc24.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.3.0-0.rc0.git9.1.fc24.x86_64 #1 SMP Tue Sep 8 17:57:29 UTC 2015 x86_64 x86_64 Alert Count 4 First Seen 2015-09-09 21:27:57 EEST Last Seen 2015-09-09 21:30:06 EEST Local ID d8312144-1221-4505-bb07-dc4e3e91e994 Raw Audit Messages type=AVC msg=audit(1441823406.359:518): avc: denied { signull } for pid=1770 comm="ibus-daemon" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 tclass=process permissive=0 Hash: gnome-shell,xdm_t,unconfined_service_t,process,signull Version-Release number of selected component: selinux-policy-3.13.1-146.fc24.noarch Additional info: reporter: libreport-2.6.2 hashmarkername: setroubleshoot kernel: 4.3.0-0.rc0.git9.1.fc24.x86_64 type: libreport
What does ps -eZ |grep unconfined_service on your system?
Created attachment 1072557 [details] """ ps -eZ | grep unconfined_service """ output
I have attached needed-info on the other hand i have already made latest updates ( <revision>1441871258</revision>) today so it might solved the bug which i have mentioned in this report thus that info might be not showing correct info related to bug
(In reply to Miroslav Grepl from comment #1) Since I just hit this > What does > > ps -eZ |grep unconfined_service > > on your system? system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1041 ? 00:00:00 gvfsd system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1050 ? 00:00:00 gvfsd-fuse system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1247 ? 00:00:00 at-spi-bus-laun system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1255 ? 00:00:00 dbus-daemon system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1258 ? 00:00:00 at-spi2-registr system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1547 ? 00:00:00 gvfs-udisks2-vo system_u:system_r:unconfined_service_t:s0 1550 ? 00:00:00 udisksd system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1558 ? 00:00:00 gvfs-gphoto2-vo system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1563 ? 00:00:00 gvfs-afc-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1569 ? 00:00:00 gvfs-goa-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1573 ? 00:00:00 goa-daemon system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1580 ? 00:00:00 goa-identity-se system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1585 ? 00:00:00 gvfs-mtp-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1789 ? 00:00:00 at-spi-bus-laun system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1793 ? 00:00:00 gvfsd system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1798 ? 00:00:00 gvfsd-fuse system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1804 ? 00:00:00 dbus-daemon system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1811 ? 00:00:00 at-spi2-registr system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1914 ? 00:00:00 gnome-shell-cal system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1919 ? 00:00:00 evolution-sourc system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1938 ? 00:00:00 goa-daemon system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1948 ? 00:00:00 goa-identity-se system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1953 ? 00:00:00 dconf-service system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1970 ? 00:00:00 gvfs-udisks2-vo system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1980 ? 00:00:00 gvfs-gphoto2-vo system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1985 ? 00:00:00 gvfs-afc-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1991 ? 00:00:00 gvfs-goa-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 1996 ? 00:00:00 gvfs-mtp-volume system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2014 ? 00:00:04 tracker-store system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2091 ? 00:00:00 evolution-calen system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2132 ? 00:00:00 evolution-calen system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2170 ? 00:00:00 evolution-addre system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2173 ? 00:00:00 evolution-calen system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2190 ? 00:00:00 gvfsd-metadata system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2195 ? 00:00:00 evolution-addre system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2277 ? 00:00:02 gnome-terminal- system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2282 pts/0 00:00:00 bash system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2356 ? 00:00:00 gconfd-2 system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2451 pts/0 00:00:09 atop system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2658 ? 00:00:00 gvfsd-http system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2693 pts/1 00:00:00 bash system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2769 pts/1 00:00:00 ps system_u:system_r:unconfined_service_t:s0-s0:c0.c1023 2770 pts/1 00:00:00 grep
This looks like the rawhide bug that I reported. on systemd.
*** This bug has been marked as a duplicate of bug 1262933 ***