Bug 783665 - SELinux is preventing /usr/bin/gnome-session from 'setattr' accesses on the None at-spi2.
Summary: SELinux is preventing /usr/bin/gnome-session from 'setattr' accesses on the N...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:370e1c963b30b791b43bfc5eae7...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2012-01-21 15:33 UTC by Nicolas Mailhot
Modified: 2012-02-20 15:58 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-02-20 15:58:06 UTC
Type: ---


Attachments (Terms of Use)

Description Nicolas Mailhot 2012-01-21 15:33:06 UTC
libreport version: 2.0.8
executable:     /usr/bin/python
hashmarkername: setroubleshoot
kernel:         3.2.1-5.fc17.x86_64
reason:         SELinux is preventing /usr/bin/gnome-session from 'setattr' accesses on the None at-spi2.
time:           sam. 21 janv. 2012 16:24:34 CET

description:
:SELinux is preventing /usr/bin/gnome-session from 'setattr' accesses on the None at-spi2.
:
:*****  Plugin catchall (100. confidence) suggests  ***************************
:
:If you believe that gnome-session should be allowed setattr access on the at-spi2 <Inconnu> by default.
:Then you should report this as a bug.
:You can generate a local policy module to allow this access.
:Do
:allow this access for now by executing:
:# grep gnome-session /var/log/audit/audit.log | audit2allow -M mypol
:# semodule -i mypol.pp
:
:Additional Information:
:Source Context                system_u:system_r:xdm_t:s0-s0:c0.c1023
:Target Context                system_u:object_r:tmp_t:s0
:Target Objects                at-spi2 [ None ]
:Source                        gnome-session
:Source Path                   /usr/bin/gnome-session
:Port                          <Inconnu>
:Host                          (removed)
:Source RPM Packages           
:Target RPM Packages           
:Policy RPM                    <Inconnu>
:Selinux Enabled               True
:Policy Type                   targeted
:Enforcing Mode                Enforcing
:Host Name                     (removed)
:Platform                      Linux (removed) 3.2.1-5.fc17.x86_64 #1 SMP Tue Jan
:                              17 18:57:18 UTC 2012 x86_64 x86_64
:Alert Count                   3
:First Seen                    sam. 21 janv. 2012 16:22:03 CET
:Last Seen                     sam. 21 janv. 2012 16:22:05 CET
:Local ID                      90cf7795-1e8d-4a31-8ba8-a7d448397b4d
:
:Raw Audit Messages
:type=AVC msg=audit(1327159325.921:131): avc:  denied  { setattr } for  pid=1470 comm="gnome-shell" name="at-spi2" dev=dm-1 ino=153787 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:tmp_t:s0 tclass=dirnode=(removed) type=SYSCALL msg=audit(1327159325.921:131): arch=c000003e syscall=90 success=no exit=-13 a0=7f556a3e6841 a1=3ff a2=11 a3=7fff60e0b9d0 items=0 ppid=1373 pid=1470 auid=42 uid=42 gid=42 euid=42 suid=42 fsuid=42 egid=42 sgid=42 fsgid=42 tty=(none) ses=1 comm="gnome-shell" exe="/usr/bin/gnome-shell" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)
:
:
:Hash: gnome-session,xdm_t,tmp_t,None,setattr
:
:audit2allow
:
:
:audit2allow -R
:
:

Comment 1 Miroslav Grepl 2012-01-23 09:10:24 UTC
Do you know what you were doing when this happened?

Have you seen this happen again or was this just after a fresh install?

Comment 2 Nicolas Mailhot 2012-01-23 15:15:51 UTC
It's not a fresh install, it's a continuously updated rawhide box

Comment 3 Miroslav Grepl 2012-01-24 09:13:54 UTC
And have you seen this happen again?

Comment 4 Nicolas Mailhot 2012-01-24 13:30:50 UTC
(In reply to comment #3)
> And have you seen this happen again?

I see it regularly yes
It's kind of hard to check if it's due to a particular event in gnome, since gnome-shell is currently failing every few minutes in rawhide, and the system is continuously tearing down and rebuilding the DE

Comment 5 Daniel Walsh 2012-01-24 16:30:18 UTC
Nicolas can you remove all content from /tmp, log out and log back in and see if you can get this to happen again.

Comment 6 JM 2012-02-15 16:57:12 UTC
I get this message on a F16 system, too.

Comment 7 Daniel Walsh 2012-02-15 19:42:42 UTC
JM can you remove all content from /tmp and logout and log back in and see if the problem goes a way.

Comment 8 JM 2012-02-18 16:50:05 UTC
I removed everything from /tmp and after a reboot it looks like the problem is fixed.


Note You need to log in before you can comment on or make changes to this bug.