Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: libselinux-3.10-1.fc44.x86_64 libselinux-utils-3.10-1.fc44.x86_64 passt-selinux-0^20260120.g386b5f5-1.fc44.noarch adcli-selinux-0.9.3.1-5.fc44.noarch libselinux-devel-3.10-1.fc44.x86_64 python3-libselinux-3.10-1.fc44.x86_64 smartmontools-selinux-7.5-6.fc44.noarch swtpm-selinux-0.10.1-3.fc44.noarch tpm2-abrmd-selinux-2.3.1-15.fc44.noarch usbguard-selinux-1.1.3-7.fc44.noarch dnfdaemon-selinux-0.3.22-11.fc44.noarch rpm-plugin-selinux-6.0.1-2.fc44.x86_64 libselinux-3.10-1.fc44.i686 container-selinux-2.247.0-1.fc44.noarch tigervnc-selinux-1.16.2-1.fc44.noarch flatpak-selinux-1.17.6-1.fc44.noarch selinux-policy-43.6-1.fc44.noarch selinux-policy-minimum-43.6-1.fc44.noarch selinux-policy-targeted-43.6-1.fc44.noarch nbdkit-selinux-1.47.7-1.fc44.noarch NetworkManager-ssh-selinux-1.4.4-1.fc44.x86_64 SELinux is preventing accounts-daemon from 'read' accesses on the lnk_file /usr/share/accountsservice/interfaces/org.freedesktop.DisplayManager.AccountsService.xml. ***** Plugin catchall (100. confidence) suggests ************************** Se si ritiene che a accounts-daemon debba essere consentito l'accesso read su lnk_file org.freedesktop.DisplayManager.AccountsService.xml per impostazione predefinita. Then si dovrebbe segnalare il problema come bug. È possibile generare un modulo di politica locale per consentire questo accesso. Do consentire questo accesso per ora eseguendo: # ausearch -c 'accounts-daemon' --raw | audit2allow -M my-$MODULE_NOME # semodule -X 300 -i mio-accountsdaemon.pp Additional Information: Source Context system_u:system_r:accountsd_t:s0 Target Context system_u:object_r:accountsd_share_t:s0 Target Objects /usr/share/accountsservice/interfaces/org.freedesk top.DisplayManager.AccountsService.xml [ lnk_file ] Source accounts-daemon Source Path accounts-daemon Port <Sconosciuto> Host (removed) Source RPM Packages Target RPM Packages lightdm-1.32.0-25.fc44.x86_64 SELinux Policy RPM selinux-policy-targeted-43.6-1.fc44.noarch Local Policy RPM selinux-policy-targeted-43.6-1.fc44.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 6.19.13-300.fc44.x86_64 #1 SMP PREEMPT_DYNAMIC Sat Apr 18 19:10:53 UTC 2026 x86_64 Alert Count 1 First Seen 2026-04-25 21:27:32 CEST Last Seen 2026-04-25 21:27:32 CEST Local ID 6b93b4b5-e6db-49c8-8b3b-ff0ceb91574d Raw Audit Messages type=AVC msg=audit(1777145252.19:73): avc: denied { read } for pid=1218 comm="accounts-daemon" name="org.freedesktop.DisplayManager.AccountsService.xml" dev="sdd4" ino=58262116 scontext=system_u:system_r:accountsd_t:s0 tcontext=system_u:object_r:accountsd_share_t:s0 tclass=lnk_file permissive=1 Hash: accounts-daemon,accountsd_t,accountsd_share_t,lnk_file,read Version-Release number of selected component: selinux-policy-targeted-43.6-1.fc44.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing accounts-daemon from 'read' accesses on the lnk_file /usr/share/accountsservice/interfaces/org.freedesktop.DisplayManager.AccountsService.xml. package: selinux-policy-targeted-43.6-1.fc44.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.19.13-300.fc44.x86_64 component: selinux-policy
Created attachment 2138242 [details] File: description
Created attachment 2138243 [details] File: os_info
*** This bug has been marked as a duplicate of bug 2458894 ***