Bug 700564 - SELinux is preventing /usr/libexec/gdm-session-worker from 'create' accesses on the ファイル .xsession-errors.XX2P8QUV.
Summary: SELinux is preventing /usr/libexec/gdm-session-worker from 'create' accesses ...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 14
Hardware: i386
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: setroubleshoot_trace_hash:4aed40b954a...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2011-04-28 16:48 UTC by bugz
Modified: 2011-05-19 21:06 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2011-04-28 18:04:30 UTC
Type: ---


Attachments (Terms of Use)

Description bugz 2011-04-28 16:48:10 UTC
SELinux is preventing /usr/libexec/gdm-session-worker from 'create' accesses on the ファイル .xsession-errors.XX2P8QUV.

*****  Plugin catchall (100. confidence) suggests  ***************************

If gdm-session-worker に、 .xsession-errors.XX2P8QUV file の create アクセスがデフォルトで許可されるべきです。   
Then これをバグをして報告すべきです。 
このアクセスを許可するために、ローカルポリシーモジュールを生成することができます。
Do
このアクセスを一時的に許可するには、以下を実行してください。:
# grep gdm-session-wor /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context                system_u:object_r:admin_home_t:s0
Target Objects                .xsession-errors.XX2P8QUV [ file ]
Source                        gdm-session-wor
Source Path                   /usr/libexec/gdm-session-worker
Port                          <不明>
Host                          (removed)
Source RPM Packages           gdm-2.32.1-2.fc14
Target RPM Packages           
Policy RPM                    selinux-policy-3.9.7-40.fc14
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 2.6.35.12-88.fc14.i686 #1 SMP
                              Thu Mar 31 22:12:38 UTC 2011 i686 i686
Alert Count                   6
First Seen                    2011年03月17日 12時55分25秒
Last Seen                     2011年04月29日 01時34分01秒
Local ID                      f4451221-27fb-4b65-adfb-44a84c7fd36e

Raw Audit Messages
type=AVC msg=audit(1304008441.363:43): avc:  denied  { create } for  pid=10271 comm="gdm-session-wor" name=".xsession-errors.XX2P8QUV" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:admin_home_t:s0 tclass=file


type=SYSCALL msg=audit(1304008441.363:43): arch=i386 syscall=open success=no exit=EACCES a0=97acdc0 a1=80c2 a2=180 a3=14 items=0 ppid=10251 pid=10271 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4 comm=gdm-session-wor exe=/usr/libexec/gdm-session-worker subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)

Hash: gdm-session-wor,xdm_t,admin_home_t,file,create

audit2allow

#============= xdm_t ==============
allow xdm_t admin_home_t:file create;

audit2allow -R

#============= xdm_t ==============
allow xdm_t admin_home_t:file create;

Comment 1 Miroslav Grepl 2011-04-28 18:04:30 UTC
Are you trying to log in as root?

This is not supported with SELinux.


Note You need to log in before you can comment on or make changes to this bug.