Summary: SELinux is preventing polkit-gnome-ma (xdm_t) "execute" polkit_grant_exec_t. Detailed Description: SELinux denied access requested by polkit-gnome-ma. It is not expected that this access is required by polkit-gnome-ma and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://fedora.redhat.com/docs/selinux-faq-fc5/#id2961385) Or you can disable SELinux protection altogether. Disabling SELinux protection is not recommended. Please file a bug report (http://bugzilla.redhat.com/bugzilla/enter_bug.cgi) against this package. Additional Information: Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023 Target Context system_u:object_r:polkit_grant_exec_t:s0 Target Objects /usr/libexec/polkit-grant-helper [ file ] Source polkit-gnome-ma Source Path /usr/libexec/polkit-gnome-manager Port <Unknown> Host (removed) Source RPM Packages PolicyKit-gnome-0.9.2-3.fc11 Target RPM Packages PolicyKit-0.9-6.fc11 Policy RPM selinux-policy-3.6.12-86.fc11 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.30.9-96.fc11.i686.PAE #1 SMP Tue Nov 3 23:41:33 EST 2009 i686 athlon Alert Count 9 First Seen Sat 31 Oct 2009 06:23:06 AM CDT Last Seen Mon 16 Nov 2009 07:12:55 PM CST Local ID a658a057-3647-469d-ade0-a05d0f9082c6 Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1258420375.75:540): avc: denied { execute } for pid=13339 comm="polkit-gnome-ma" name="polkit-grant-helper" dev=dm-0 ino=731 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:polkit_grant_exec_t:s0 tclass=file node=(removed) type=SYSCALL msg=audit(1258420375.75:540): arch=40000003 syscall=11 success=no exit=-13 a0=3f67194 a1=bfc137d4 a2=81fa540 a3=3f67194 items=0 ppid=13338 pid=13339 auid=4294967295 uid=42 gid=479 euid=42 suid=42 fsuid=42 egid=479 sgid=479 fsgid=479 tty=(none) ses=4294967295 comm="polkit-gnome-ma" exe="/usr/libexec/polkit-gnome-manager" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null) Hash String generated from selinux-policy-3.6.12-86.fc11,catchall,polkit-gnome-ma,xdm_t,polkit_grant_exec_t,file,execute audit2allow suggests: #============= xdm_t ============== allow xdm_t polkit_grant_exec_t:file execute;
*** This bug has been marked as a duplicate of bug 538428 ***