In my fresh & clean f8 install, I get a slew of selinux errors related 'gdm' both during startup and at intervals thereafter. Here is a list of them (after piping through sort and uniq): avc: denied { getattr } comm="gdm" path="/bin/rpm" dev=sda7 ino=1035336 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/cancel.cups" dev=sda7 ino=1380622 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:lpr_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/cvs" dev=sda7 ino=1378511 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:cvs_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/mplayer" dev=sda7 ino=1368339 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:mplayer_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/rsync" dev=sda7 ino=1379578 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rsync_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/screen" dev=sda7 ino=1366280 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:screen_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/ssh" dev=sda7 ino=1382080 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:ssh_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/bin/yum" dev=sda7 ino=1382847 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:rpm_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm" path="/usr/lib/jvm/java-1.7.0-icedtea-1.7.0.0/jre/bin/java" dev=sda7 ino=1781548 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:java_exec_t:s0 tclass=file avc: denied { getattr } comm="gdm-binary" path="/root2" dev=sda7 ino=1164699 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:default_t:s0 tclass=dir avc: denied { signal } comm="gdm-binary" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:system_r:mono_t:s0 tclass=process
If you chcon -t bin_t /usr/sbin/gdm And then restart gdm, do you still get these avc messages? This fix is in selinux-policy-3.0.8-57.fc8
The latest policy, indeed seems to have fixed it. Thanks.
Can we close this bug since seems to be fixed...