Bug 429888 - SELinux is preventing gconfd-2(/usr/libexec/gconfd-2) (xdm_t) "create" to <Unknown> (var_lib_t)
SELinux is preventing gconfd-2(/usr/libexec/gconfd-2) (xdm_t) "create" to <Un...
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted (Show other bugs)
All Linux
low Severity low
: ---
: ---
Assigned To: Daniel Walsh
Ben Levenson
Depends On:
  Show dependency treegraph
Reported: 2008-01-23 11:46 EST by Zack Cerza
Modified: 2008-01-24 16:06 EST (History)
0 users

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-01-24 16:06:41 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Zack Cerza 2008-01-23 11:46:00 EST
Description of problem:
This one is even more mysterious than usual to me...

Version-Release number of selected component (if applicable):

Additional info:
host=tak type=AVC msg=audit(1201104228.173:206): avc: denied { create } for
pid=2969 comm="gconfd-2" name="apps"
tcontext=system_u:object_r:var_lib_t:s0 tclass=dir 

host=tak type=SYSCALL msg=audit(1201104228.173:206): arch=40000003 syscall=39
success=yes exit=0 a0=954aa20 a1=1c0 a2=44ba44 a3=9557e30 items=0 ppid=1
pid=2969 auid=4294967295 uid=42 gid=42 euid=42 suid=42 fsuid=42 egid=42 sgid=42
fsgid=42 tty=(none) comm="gconfd-2" exe="/usr/libexec/gconfd-2"
subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)
Comment 1 Daniel Walsh 2008-01-23 15:27:08 EST
Do you know what directory it is creating?

Comment 2 Zack Cerza 2008-01-23 16:06:48 EST
I'd guess, since that's what the message seems to say. But I've been running in
permissive mode since I hit some more serious problems which I've reported, and
I have no /var/lib/apps.
Comment 3 Daniel Walsh 2008-01-24 14:21:02 EST
restorecon -R -v /var/lib/gdm

Comment 4 Zack Cerza 2008-01-24 15:11:18 EST
I did do an autorelabel, and I haven't seen the message since. But is there a
way to avoid this breakage on other F8->F9 upgrades?
Comment 5 Daniel Walsh 2008-01-24 16:06:41 EST
I am hoping that F8-f9 will cause a relabel of this directory.

Note You need to log in before you can comment on or make changes to this bug.