Summary: SELinux is preventing /usr/sbin/gdm-binary "create" access on gdm. Detailed Description: SELinux denied access requested by gdm-binary. It is not expected that this access is required by gdm-binary and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. Allowing Access: You can generate a local policy module to allow this access - see FAQ (http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Please file a bug report. Additional Information: Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023 Target Context system_u:object_r:var_log_t:s0 Target Objects gdm [ dir ] Source gdm-binary Source Path /usr/sbin/gdm-binary Port <Unknown> Host (removed) Source RPM Packages gdm-2.30.2-1.fc13 Target RPM Packages Policy RPM selinux-policy-3.7.19-41.fc13 Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Plugin Name catchall Host Name (removed) Platform Linux thinkpad 2.6.33.6-147.2.4.fc13.x86_64 #1 SMP Fri Jul 23 17:14:44 UTC 2010 x86_64 x86_64 Alert Count 15 First Seen Thu 05 Aug 2010 09:01:00 AM CEST Last Seen Sat 14 Aug 2010 08:54:46 AM CEST Local ID bf5f123e-62c8-4c7e-8466-7891c546f859 Line Numbers Raw Audit Messages node=thinkpad type=AVC msg=audit(1281768886.277:14): avc: denied { create } for pid=1580 comm="gdm-binary" name="gdm" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_log_t:s0 tclass=dir node=thinkpad type=SYSCALL msg=audit(1281768886.277:14): arch=c000003e syscall=83 success=no exit=-13 a0=419d54 a1=1ed a2=ffffffffffffffa8 a3=7fff39c3bfe0 items=0 ppid=1 pid=1580 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="gdm-binary" exe="/usr/sbin/gdm-binary" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null) Hash String generated from catchall,gdm-binary,xdm_t,var_log_t,dir,create audit2allow suggests: #============= xdm_t ============== allow xdm_t var_log_t:dir create;
Some how you /var/log/gdm directory got mislabeled. restorecon -R -v /var/log Should fix. Reopen if this happens again.
*** Bug 624226 has been marked as a duplicate of this bug. ***