Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: Waking up laptop from standby SELinux is preventing rtkit-daemon from 'sys_nice' accesses on the cap_userns Unbekannt. ***** Plugin catchall (100. confidence) suggests ************************** Wenn Sie denken, dass es rtkit-daemon standardmäßig erlaubt sein sollte, sys_nice Zugriff auf Unbekannt cap_userns zu erhalten. Then sie sollten dies als Fehler melden. Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen. Do zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen: # ausearch -c 'rtkit-daemon' --raw | audit2allow -M my-rtkitdaemon # semodule -X 300 -i my-rtkitdaemon.pp Additional Information: Source Context system_u:system_r:rtkit_daemon_t:s0 Target Context system_u:system_r:rtkit_daemon_t:s0 Target Objects Unbekannt [ cap_userns ] Source rtkit-daemon Source Path rtkit-daemon Port <Unbekannt> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.14.4-31.fc31.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 5.3.0-0.rc6.git0.1.fc31.x86_64 #1 SMP Mon Aug 26 13:01:25 UTC 2019 x86_64 x86_64 Alert Count 44 First Seen 2019-09-13 19:17:26 CEST Last Seen 2019-09-16 19:16:41 CEST Local ID 126f06f3-c17b-4cb7-868a-7d07ed68d2f1 Raw Audit Messages type=AVC msg=audit(1568654201.692:314): avc: denied { sys_nice } for pid=1113 comm="rtkit-daemon" capability=23 scontext=system_u:system_r:rtkit_daemon_t:s0 tcontext=system_u:system_r:rtkit_daemon_t:s0 tclass=cap_userns permissive=0 Hash: rtkit-daemon,rtkit_daemon_t,rtkit_daemon_t,cap_userns,sys_nice Version-Release number of selected component: selinux-policy-3.14.4-31.fc31.noarch Additional info: component: selinux-policy reporter: libreport-2.10.1 hashmarkername: setroubleshoot kernel: 5.3.0-0.rc6.git0.1.fc31.x86_64 type: libreport Potential duplicate: bug 1750024
*** This bug has been marked as a duplicate of bug 1750024 ***