Fedora Account System
Red Hat Associate
Red Hat Customer
Summary SELinux is preventing pam_console_app (pam_console_t) "getattr" to / (fs_t). Detailed Description SELinux denied access requested by pam_console_app. It is not expected that this access is required by pam_console_app and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access You can generate a local policy module to allow this access - see http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385 Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a http://bugzilla.redhat.com/bugzilla/enter_bug.cgi against this package. Additional Information Source Context system_u:system_r:pam_console_t:SystemLow- SystemHigh Target Context system_u:object_r:fs_t Target Objects / [ filesystem ] Affected RPM Packages filesystem-2.4.6-1.fc7 [target] Policy RPM selinux-policy-2.6.4-30.fc7 Selinux Enabled True Policy Type targeted MLS Enabled True Enforcing Mode Enforcing Plugin Name plugins.catchall Host Name localhost.localdomain Platform Linux localhost.localdomain 2.6.22.1-41.fc7 #1 SMP Fri Jul 27 18:10:34 EDT 2007 i686 i686 Alert Count 30 First Seen Sat 16 Jun 2007 03:28:09 PM PDT Last Seen Mon 06 Aug 2007 09:26:11 PM PDT Local ID 7f2e2cf3-2cd7-4678-830f-0f33f97fa851 Line Numbers Raw Audit Messages avc: denied { getattr } for comm="pam_console_app" dev=sdb5 name="/" pid=2451 scontext=system_u:system_r:pam_console_t:s0-s0:c0.c1023 tclass=filesystem tcontext=system_u:object_r:fs_t:s0
Fixed in selinux-policy-2.6.4-34.fc7
Moving modified bugs to closed