Red Hat Bugzilla – Bug 1504074
cannot start zabbix server because of setrlimit syscall blocked by selinux
Last modified: 2018-04-10 08:45:39 EDT
Description of problem: The zabbix server is unable to start. The setrlimit syscall is prevented by SELinux from executing. Version-Release number of selected component (if applicable): RHEL 7.4 How reproducible: always Steps to Reproduce: 1. start zabbix server Actual results: type=AVC msg=audit(1505788100.774:11853): avc: denied { setrlimit } for pid=27418 comm="zabbix_server" scontext=system_u:system_r:zabbix_t:s0 tcontext=system_u:system_r:zabbix_t:s0 tclass=process Expected results: <no avc> Additional info: sesearch -s zabbix_t -t zabbix_t -c process -A Found 1 semantic av rules: allow zabbix_t zabbix_t : process { fork sigchld sigkill sigstop signull signal getsched setsched setpgid getcap } ; Unlike bz 1393332, this issue is regarding zabbix server and the zabbix_t domain.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0763