libreport version: 2.0.10 executable: /usr/bin/python2.7 hashmarkername: setroubleshoot kernel: 3.5.0-2.fc17.x86_64 time: Fri 03 Aug 2012 11:51:18 BST description: :SELinux is preventing /usr/bin/totem-video-thumbnailer from 'name_connect' accesses on the tcp_socket . : :***** Plugin catchall (100. confidence) suggests *************************** : :If you believe that totem-video-thumbnailer should be allowed name_connect access on the tcp_socket by default. :Then you should report this as a bug. :You can generate a local policy module to allow this access. :Do :allow this access for now by executing: :# grep totem-video-thu /var/log/audit/audit.log | audit2allow -M mypol :# semodule -i mypol.pp : :Additional Information: :Source Context unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 :Target Context system_u:object_r:xserver_port_t:s0 :Target Objects [ tcp_socket ] :Source totem-video-thu :Source Path /usr/bin/totem-video-thumbnailer :Port 6010 :Host (removed) :Source RPM Packages totem-3.4.3-1.fc17.x86_64 :Target RPM Packages :Policy RPM selinux-policy-3.10.0-142.fc17.noarch :Selinux Enabled True :Policy Type targeted :Enforcing Mode Enforcing :Host Name (removed) :Platform Linux (removed) 3.5.0-2.fc17.x86_64 #1 SMP : Mon Jul 30 14:48:59 UTC 2012 x86_64 x86_64 :Alert Count 12 :First Seen Fri 03 Aug 2012 08:52:12 BST :Last Seen Fri 03 Aug 2012 08:52:16 BST :Local ID d37feff5-13fd-47d6-ac8d-ea79ab8f831a : :Raw Audit Messages :type=AVC msg=audit(1343980336.417:967): avc: denied { name_connect } for pid=7945 comm="totem-video-thu" dest=6010 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:xserver_port_t:s0 tclass=tcp_socket : : :type=SYSCALL msg=audit(1343980336.417:967): arch=x86_64 syscall=connect success=no exit=EACCES a0=3 a1=2260c20 a2=10 a3=7fffd9e326f4 items=0 ppid=7804 pid=7945 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 tty=pts0 ses=53 comm=totem-video-thu exe=/usr/bin/totem-video-thumbnailer subj=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 key=(null) : :Hash: totem-video-thu,thumb_t,xserver_port_t,tcp_socket,name_connect : :audit2allow : :#============= thumb_t ============== :allow thumb_t xserver_port_t:tcp_socket name_connect; : :audit2allow -R : :#============= thumb_t ============== :allow thumb_t xserver_port_t:tcp_socket name_connect; :
Did the video play?
I think so, yes. Although I only noticed the setroubleshoot alert later so I'm not really sure which video it relates to.
And did it work?
repeat Comment 2.
Ok, let's close it for now and re-open if this happens again. Thank you.