The following was filed automatically by setroubleshoot: Summary: SELinux is preventing /usr/bin/nspluginscan "add_name" access on pluginsinfo.lock.MT1571. Detailed Description: [SELinux is in permissive mode. This access was not denied.] SELinux denied access requested by nspluginscan. It is not expected that this access is required by nspluginscan and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context unconfined_u:unconfined_r:nsplugin_t:s0-s0:c0.c102 3 Target Context unconfined_u:object_r:admin_home_t:s0 Target Objects pluginsinfo.lock.MT1571 [ dir ] Source nspluginscan Source Path /usr/bin/nspluginscan Port <Unknown> Host (removed) Source RPM Packages kdebase-4.3.1-2.fc12 Target RPM Packages Policy RPM selinux-policy-3.6.31-3.fc12 Selinux Enabled True Policy Type targeted MLS Enabled True Enforcing Mode Permissive Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.31-12.fc12.i686 #1 SMP Mon Sep 14 02:27:06 EDT 2009 i686 athlon Alert Count 2 First Seen Wed 16 Sep 2009 04:49:15 AM BST Last Seen Wed 16 Sep 2009 04:49:15 AM BST Local ID 36e39eec-8bd7-4617-8c25-199a371108f1 Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1253072955.98:46): avc: denied { add_name } for pid=1571 comm="nspluginscan" name="pluginsinfo.lock.MT1571" scontext=unconfined_u:unconfined_r:nsplugin_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=dir node=(removed) type=AVC msg=audit(1253072955.98:46): avc: denied { create } for pid=1571 comm="nspluginscan" name="pluginsinfo.lock.MT1571" scontext=unconfined_u:unconfined_r:nsplugin_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file node=(removed) type=SYSCALL msg=audit(1253072955.98:46): arch=40000003 syscall=5 success=yes exit=9 a0=9800670 a1=880c2 a2=180 a3=980068f items=0 ppid=1513 pid=1571 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="nspluginscan" exe="/usr/bin/nspluginscan" subj=unconfined_u:unconfined_r:nsplugin_t:s0-s0:c0.c1023 key=(null) audit2allow suggests: #============= nsplugin_t ============== allow nsplugin_t admin_home_t:dir add_name; allow nsplugin_t admin_home_t:file create;
If this happened during a yum update then it should be Fixed in selinux-policy-3.6.32-1.fc12.noarch If you are logging as root and running firefox, don't do that.
*** Bug 523730 has been marked as a duplicate of this bug. ***
*** Bug 523731 has been marked as a duplicate of this bug. ***
*** Bug 523732 has been marked as a duplicate of this bug. ***
*** Bug 523733 has been marked as a duplicate of this bug. ***
*** Bug 523735 has been marked as a duplicate of this bug. ***
*** Bug 523737 has been marked as a duplicate of this bug. ***
*** Bug 523738 has been marked as a duplicate of this bug. ***
*** Bug 523739 has been marked as a duplicate of this bug. ***
*** Bug 523740 has been marked as a duplicate of this bug. ***