Bug 671792 - SELinux is preventing /usr/bin/nautilus "getattr" access on /proc/<pid>.
Summary: SELinux is preventing /usr/bin/nautilus "getattr" access on /proc/<pid>.
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 13
Hardware: i386
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:a43955ef149...
: 671793 671794 671795 671796 671797 671798 671799 671800 671801 671802 671803 671804 671805 671806 671807 671808 671809 671810 671812 671813 671814 671815 671816 671817 671818 671819 671820 671822 671823 671824 671825 671826 671827 671828 671829 671830 671831 671832 671833 671834 671835 671836 671837 671838 671839 671840 671841 671842 671843 671844 671845 671846 671847 671848 671849 671850 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-01-22 07:45 UTC by maurizio
Modified: 2011-01-24 14:08 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-01-24 13:53:19 UTC
Type: ---


Attachments (Terms of Use)

Description maurizio 2011-01-22 07:45:19 UTC
Summary:

SELinux is preventing /usr/bin/nautilus "getattr" access on /proc/.

Detailed Description:

[SELinux is in permissive mode. This access was not denied.]

SELinux denied access requested by nautilus. It is not expected that this access
is required by nautilus and this access may signal an intrusion attempt. It is
also possible that the specific version or configuration of the application is
causing it to require additional access.

Allowing Access:

You can generate a local policy module to allow this access - see FAQ
(http://docs.fedoraproject.org/selinux-faq-fc5/#id2961385) Please file a bug
report.

Additional Information:

Source Context                sysadm_u:sysadm_r:oddjob_mkhomedir_t:s0-s0:c0.c102
                              3
Target Context                system_u:system_r:inetd_t:s0-s0:c0.c1023
Target Objects                /proc/<pid> [ dir ]
Source                        nautilus
Source Path                   /usr/bin/nautilus
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           nautilus-2.30.1-3.fc13
Target RPM Packages           
Policy RPM                    selinux-policy-3.7.19-69.fc13
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Permissive
Plugin Name                   catchall
Host Name                     (removed)
Platform                      Linux (removed) 2.6.34.7-61.fc13.i686
                              #1 SMP Tue Oct 19 04:42:47 UTC 2010 i686 i686
Alert Count                   2
First Seen                    Thu 20 Jan 2011 11:15:00 PM MST
Last Seen                     Thu 20 Jan 2011 11:24:42 PM MST
Local ID                      022c7044-c564-47b8-92b8-a7c9aebaa008
Line Numbers                  

Raw Audit Messages            

node=(removed) type=AVC msg=audit(1295591082.275:26408): avc:  denied  { getattr } for  pid=2922 comm="nautilus" path="/proc/1394" dev=proc ino=13167 scontext=sysadm_u:sysadm_r:oddjob_mkhomedir_t:s0-s0:c0.c1023 tcontext=system_u:system_r:inetd_t:s0-s0:c0.c1023 tclass=dir

node=(removed) type=SYSCALL msg=audit(1295591082.275:26408): arch=40000003 syscall=196 success=yes exit=0 a0=b0805858 a1=ae99bf6c a2=f7bff4 a3=b081f108 items=0 ppid=1767 pid=2922 auid=500 uid=500 gid=493 euid=500 suid=500 fsuid=500 egid=493 sgid=493 fsgid=493 tty=(none) ses=1 comm="nautilus" exe="/usr/bin/nautilus" subj=sysadm_u:sysadm_r:oddjob_mkhomedir_t:s0-s0:c0.c1023 key=(null)



Hash String generated from  catchall,nautilus,oddjob_mkhomedir_t,inetd_t,dir,getattr
audit2allow suggests:

#============= oddjob_mkhomedir_t ==============
allow oddjob_mkhomedir_t inetd_t:dir getattr;

Comment 1 Daniel Walsh 2011-01-24 13:53:19 UTC
SOmething on your machine is badly mislabeled, you need to relabel the system

touch /.autorelabel; reboot

Comment 2 Daniel Walsh 2011-01-24 13:55:27 UTC
And please do not report hundreds of bugs that all look the same, this wastes our time and yours.  Report one bug and mention in the bug report that you have lots of similar bugs.

Comment 3 Daniel Walsh 2011-01-24 13:55:34 UTC
*** Bug 671793 has been marked as a duplicate of this bug. ***

Comment 4 Daniel Walsh 2011-01-24 13:55:44 UTC
*** Bug 671794 has been marked as a duplicate of this bug. ***

Comment 5 Daniel Walsh 2011-01-24 13:55:51 UTC
*** Bug 671796 has been marked as a duplicate of this bug. ***

Comment 6 Daniel Walsh 2011-01-24 13:55:59 UTC
*** Bug 671795 has been marked as a duplicate of this bug. ***

Comment 7 Daniel Walsh 2011-01-24 13:56:06 UTC
*** Bug 671797 has been marked as a duplicate of this bug. ***

Comment 8 Daniel Walsh 2011-01-24 13:56:16 UTC
*** Bug 671798 has been marked as a duplicate of this bug. ***

Comment 9 Daniel Walsh 2011-01-24 13:56:24 UTC
*** Bug 671799 has been marked as a duplicate of this bug. ***

Comment 10 Daniel Walsh 2011-01-24 13:56:33 UTC
*** Bug 671800 has been marked as a duplicate of this bug. ***

Comment 11 Daniel Walsh 2011-01-24 13:56:43 UTC
*** Bug 671801 has been marked as a duplicate of this bug. ***

Comment 12 Daniel Walsh 2011-01-24 13:56:54 UTC
*** Bug 671802 has been marked as a duplicate of this bug. ***

Comment 13 Daniel Walsh 2011-01-24 13:57:03 UTC
*** Bug 671803 has been marked as a duplicate of this bug. ***

Comment 14 Daniel Walsh 2011-01-24 13:57:12 UTC
*** Bug 671804 has been marked as a duplicate of this bug. ***

Comment 15 Daniel Walsh 2011-01-24 13:57:21 UTC
*** Bug 671805 has been marked as a duplicate of this bug. ***

Comment 16 Daniel Walsh 2011-01-24 13:57:30 UTC
*** Bug 671806 has been marked as a duplicate of this bug. ***

Comment 17 Daniel Walsh 2011-01-24 14:00:33 UTC
*** Bug 671807 has been marked as a duplicate of this bug. ***

Comment 18 Daniel Walsh 2011-01-24 14:00:43 UTC
*** Bug 671808 has been marked as a duplicate of this bug. ***

Comment 19 Daniel Walsh 2011-01-24 14:00:51 UTC
*** Bug 671809 has been marked as a duplicate of this bug. ***

Comment 20 Daniel Walsh 2011-01-24 14:00:58 UTC
*** Bug 671810 has been marked as a duplicate of this bug. ***

Comment 21 Daniel Walsh 2011-01-24 14:01:06 UTC
*** Bug 671812 has been marked as a duplicate of this bug. ***

Comment 22 Daniel Walsh 2011-01-24 14:01:14 UTC
*** Bug 671813 has been marked as a duplicate of this bug. ***

Comment 23 Daniel Walsh 2011-01-24 14:01:25 UTC
*** Bug 671814 has been marked as a duplicate of this bug. ***

Comment 24 Daniel Walsh 2011-01-24 14:01:33 UTC
*** Bug 671815 has been marked as a duplicate of this bug. ***

Comment 25 Daniel Walsh 2011-01-24 14:01:41 UTC
*** Bug 671816 has been marked as a duplicate of this bug. ***

Comment 26 Daniel Walsh 2011-01-24 14:01:49 UTC
*** Bug 671817 has been marked as a duplicate of this bug. ***

Comment 27 Daniel Walsh 2011-01-24 14:01:56 UTC
*** Bug 671818 has been marked as a duplicate of this bug. ***

Comment 28 Daniel Walsh 2011-01-24 14:02:04 UTC
*** Bug 671819 has been marked as a duplicate of this bug. ***

Comment 29 Daniel Walsh 2011-01-24 14:02:12 UTC
*** Bug 671820 has been marked as a duplicate of this bug. ***

Comment 30 Daniel Walsh 2011-01-24 14:02:22 UTC
*** Bug 671822 has been marked as a duplicate of this bug. ***

Comment 31 Daniel Walsh 2011-01-24 14:02:30 UTC
*** Bug 671823 has been marked as a duplicate of this bug. ***

Comment 32 Daniel Walsh 2011-01-24 14:02:45 UTC
*** Bug 671824 has been marked as a duplicate of this bug. ***

Comment 33 Daniel Walsh 2011-01-24 14:02:52 UTC
*** Bug 671825 has been marked as a duplicate of this bug. ***

Comment 34 Daniel Walsh 2011-01-24 14:03:06 UTC
*** Bug 671826 has been marked as a duplicate of this bug. ***

Comment 35 Daniel Walsh 2011-01-24 14:03:09 UTC
*** Bug 671827 has been marked as a duplicate of this bug. ***

Comment 36 Daniel Walsh 2011-01-24 14:03:16 UTC
*** Bug 671828 has been marked as a duplicate of this bug. ***

Comment 37 Daniel Walsh 2011-01-24 14:03:24 UTC
*** Bug 671829 has been marked as a duplicate of this bug. ***

Comment 38 Daniel Walsh 2011-01-24 14:03:31 UTC
*** Bug 671830 has been marked as a duplicate of this bug. ***

Comment 39 Daniel Walsh 2011-01-24 14:03:39 UTC
*** Bug 671831 has been marked as a duplicate of this bug. ***

Comment 40 Daniel Walsh 2011-01-24 14:03:59 UTC
*** Bug 671832 has been marked as a duplicate of this bug. ***

Comment 41 Daniel Walsh 2011-01-24 14:04:07 UTC
*** Bug 671833 has been marked as a duplicate of this bug. ***

Comment 42 Daniel Walsh 2011-01-24 14:04:16 UTC
*** Bug 671834 has been marked as a duplicate of this bug. ***

Comment 43 Daniel Walsh 2011-01-24 14:04:24 UTC
*** Bug 671835 has been marked as a duplicate of this bug. ***

Comment 44 Daniel Walsh 2011-01-24 14:04:33 UTC
*** Bug 671836 has been marked as a duplicate of this bug. ***

Comment 45 Daniel Walsh 2011-01-24 14:04:46 UTC
*** Bug 671837 has been marked as a duplicate of this bug. ***

Comment 46 Daniel Walsh 2011-01-24 14:07:17 UTC
*** Bug 671838 has been marked as a duplicate of this bug. ***

Comment 47 Daniel Walsh 2011-01-24 14:07:24 UTC
*** Bug 671839 has been marked as a duplicate of this bug. ***

Comment 48 Daniel Walsh 2011-01-24 14:07:32 UTC
*** Bug 671840 has been marked as a duplicate of this bug. ***

Comment 49 Daniel Walsh 2011-01-24 14:07:39 UTC
*** Bug 671841 has been marked as a duplicate of this bug. ***

Comment 50 Daniel Walsh 2011-01-24 14:07:47 UTC
*** Bug 671842 has been marked as a duplicate of this bug. ***

Comment 51 Daniel Walsh 2011-01-24 14:07:53 UTC
*** Bug 671843 has been marked as a duplicate of this bug. ***

Comment 52 Daniel Walsh 2011-01-24 14:08:01 UTC
*** Bug 671844 has been marked as a duplicate of this bug. ***

Comment 53 Daniel Walsh 2011-01-24 14:08:10 UTC
*** Bug 671845 has been marked as a duplicate of this bug. ***

Comment 54 Daniel Walsh 2011-01-24 14:08:16 UTC
*** Bug 671846 has been marked as a duplicate of this bug. ***

Comment 55 Daniel Walsh 2011-01-24 14:08:25 UTC
*** Bug 671847 has been marked as a duplicate of this bug. ***

Comment 56 Daniel Walsh 2011-01-24 14:08:31 UTC
*** Bug 671848 has been marked as a duplicate of this bug. ***

Comment 57 Daniel Walsh 2011-01-24 14:08:39 UTC
*** Bug 671849 has been marked as a duplicate of this bug. ***

Comment 58 Daniel Walsh 2011-01-24 14:08:49 UTC
*** Bug 671850 has been marked as a duplicate of this bug. ***

Comment 59 Daniel Walsh 2011-01-24 14:08:57 UTC
*** Bug 671882 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.