Summary: SELinux is preventing /sbin/setfiles "relabelto" access on debug. Detailed Description: SELinux denied access requested by restorecon. It is not expected that this access is required by restorecon and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context unconfined_u:system_r:setfiles_t:s0-s0:c0.c1023 Target Context system_u:object_r:debugfs_t:s0 Target Objects debug [ dir ] Source restorecon Source Path /sbin/setfiles Port <Unknown> Host (removed) Source RPM Packages policycoreutils-2.0.83-3.fc14 Target RPM Packages Policy RPM selinux-policy-3.8.7-2.fc14 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux (removed) 2.6.35-0.40.rc5.git1.fc14.i686.PAE #1 SMP Thu Jul 15 12:53:43 UTC 2010 i686 i686 Alert Count 1 First Seen Tue 20 Jul 2010 07:34:20 PM CEST Last Seen Tue 20 Jul 2010 07:34:20 PM CEST Local ID 85e8a65e-1f5a-46f8-b07f-f60c319705c9 Line Numbers Raw Audit Messages node=(removed) type=AVC msg=audit(1279647260.762:26): avc: denied { relabelto } for pid=2763 comm="restorecon" name="debug" dev=sysfs ino=53 scontext=unconfined_u:system_r:setfiles_t:s0-s0:c0.c1023 tcontext=system_u:object_r:debugfs_t:s0 tclass=dir node=(removed) type=SYSCALL msg=audit(1279647260.762:26): arch=40000003 syscall=227 success=no exit=-13 a0=120e468 a1=85d225 a2=1191b08 a3=1f items=0 ppid=2729 pid=2763 auid=500 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=pts0 ses=1 comm="restorecon" exe="/sbin/setfiles" subj=unconfined_u:system_r:setfiles_t:s0-s0:c0.c1023 key=(null) Hash String generated from catchall,restorecon,setfiles_t,debugfs_t,dir,relabelto audit2allow suggests: #============= setfiles_t ============== allow setfiles_t debugfs_t:dir relabelto;
selinux-policy-3.8.7-3.fc14.noarch rawhide.x86_64
Fixed in selinux-policy-3.8.8-2.fc14.src.rpm