Bug 1871351 - avc: denied { getattr } for cockpit-session name="/"
Summary: avc: denied { getattr } for cockpit-session name="/"
Keywords:
Status: CLOSED DUPLICATE of bug 1853730
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 33
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-08-22 16:50 UTC by Matej Marušák
Modified: 2020-08-24 07:07 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2020-08-24 07:07:01 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Matej Marušák 2020-08-22 16:50:24 UTC
Description of problem:
In Cockpit team we try to introduce Fedora 33 testing image and we see the following AVC almost on every test:
```
audit: type=1400 audit(1598040477.581:21013): avc:  denied  { getattr } for  pid=75817 comm="cockpit-session" name="/" dev="proc" ino=1 scontext=system_u:system_r:cockpit_session_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=filesystem permissive=0
```

Version-Release number of selected component (if applicable):
selinux-policy-3.14.6-24.fc33.noarch


How reproducible:
Seems that just login into Cockpit is enough. Haven't looked yet what exactly triggers this.

Comment 1 Zdenek Pytela 2020-08-24 07:07:01 UTC

*** This bug has been marked as a duplicate of bug 1853730 ***


Note You need to log in before you can comment on or make changes to this bug.