Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: SELinux is preventing /usr/sbin/rpc.gssd "module_request" access. Detailed Description: [rpc.gssd has a permissive type (gssd_t). This access was not denied.] SELinux denied access requested by rpc.gssd. It is not expected that this access is required by rpc.gssd and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context system_u:system_r:gssd_t:s0 Target Context system_u:system_r:kernel_t:s0 Target Objects None [ system ] Source rpc.gssd Source Path /usr/sbin/rpc.gssd Port <Unknown> Host (removed) Source RPM Packages nfs-utils-1.2.0-18.fc12 Target RPM Packages Policy RPM selinux-policy-3.6.32-41.fc12 Selinux Enabled True Policy Type targeted MLS Enabled True Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.31.5-122.fc12.x86_64 #1 SMP Thu Nov 5 01:37:34 EST 2009 x86_64 x86_64 Alert Count 4 First Seen Fri 06 Nov 2009 19:42:44 CET Last Seen Sat 07 Nov 2009 20:30:47 CET Local ID f5f57706-d7c2-4305-9f3a-0c70422344ad Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1257622247.26:28110): avc: denied { module_request } for pid=1518 comm="rpc.gssd" scontext=system_u:system_r:gssd_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=system node=(removed) type=AVC msg=audit(1257622247.26:28110): avc: denied { module_request } for pid=1518 comm="rpc.gssd" scontext=system_u:system_r:gssd_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=system node=(removed) type=SYSCALL msg=audit(1257622247.26:28110): arch=c000003e syscall=1 success=yes exit=4294967424 a0=7 a1=7f35be9bc550 a2=6d a3=7fff4c2cc8a0 items=0 ppid=1 pid=1518 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="rpc.gssd" exe="/usr/sbin/rpc.gssd" subj=system_u:system_r:gssd_t:s0 key=(null) Hash String generated from selinux-policy-3.6.32-41.fc12,catchall,rpc.gssd,gssd_t,kernel_t,system,module_request audit2allow suggests: #============= gssd_t ============== allow gssd_t kernel_t:system module_request;
Same scenario as 533606.
*** This bug has been marked as a duplicate of bug 527936 ***