Fedora Account System
Red Hat Associate
Red Hat Customer
Additional info: libreport version: 2.0.17 kernel: 3.6.3-1.fc17.x86_64
Created attachment 636849 [details] File: type
Created attachment 636850 [details] File: hashmarkername
I sent SIGHUP to packagekit process (via 'SystemMonitor', not terminal), and then got this error. But previously I ordinary sent this signal, and window used to pop up with password reques. # grep ksysguardproces /var/log/audit/audit.log | audit2allow -M mypol Nothing to do
Could you attach the avc's. ausearch -m avc
time->Tue Nov 6 15:23:37 2012 type=SYSCALL msg=audit(1352201017.855:83): arch=c000003e syscall=2 success=no exit=-13 a0=7f0ae5eb16ca a1=80000 a2=1b6 a3=238 items=0 ppid=2073 pid=2074 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ksysguardproces" exe="/usr/libexec/kde4/ksysguardprocesslist_helper" subj=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1352201017.855:83): avc: denied { read } for pid=2074 comm="ksysguardproces" na="passwd" dev="sda7" ino=46258 scontext=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 tcontext=sysm_u:object_r:passwd_file_t:s0 tclass=file ---- time->Tue Nov 6 15:23:37 2012 type=SYSCALL msg=audit(1352201017.855:84): arch=c000003e syscall=2 success=no exit=-13 a0=7f0ae5eb16ca1=80000 a2=1b6 a3=238 items=0 ppid=2073 pid=2074 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 ed=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ksysguardproces" exe="/usr/libexec/kde4/ksysguardpcesslist_helper" subj=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1352201017.855:84): avc: denied { read } for pid=2074 comm="ksysguardproces" na="passwd" dev="sda7" ino=46258 scontext=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 tcontext=sysm_u:object_r:passwd_file_t:s0 tclass=file ---- time->Tue Nov 6 15:23:38 2012 type=SYSCALL msg=audit(1352201018.157:86): arch=c000003e syscall=2 success=no exit=-13 a0=7f83455186ca1=80000 a2=1b6 a3=238 items=0 ppid=2078 pid=2079 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 ed=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ksysguardproces" exe="/usr/libexec/kde4/ksysguardpcesslist_helper" subj=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1352201018.157:86): avc: denied { read } for pid=2079 comm="ksysguardproces" na="passwd" dev="sda7" ino=46258 scontext=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 tcontext=sysm_u:object_r:passwd_file_t:s0 tclass=file ---- time->Tue Nov 6 15:23:38 2012 type=SYSCALL msg=audit(1352201018.158:87): arch=c000003e syscall=2 success=no exit=-13 a0=7f83455186ca1=80000 a2=1b6 a3=238 items=0 ppid=2078 pid=2079 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 ed=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="ksysguardproces" exe="/usr/libexec/kde4/ksysguardpcesslist_helper" subj=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1352201018.158:87): avc: denied { read } for pid=2079 comm="ksysguardproces" na="passwd" dev="sda7" ino=46258 scontext=system_u:system_r:gnomesystemmm_t:s0-s0:c0.c1023 tcontext=sysm_u:object_r:passwd_file_t:s0 tclass=file
Added. commit 4179ed3994c3e2ba041dfe42cd2a8631ceddc528 Author: Miroslav Grepl <mgrepl> Date: Wed Nov 7 12:44:20 2012 +0100 gnomessytemmm_t needs to read /etc/passwd
selinux-policy-3.10.0-161.fc17 has been submitted as an update for Fedora 17. https://admin.fedoraproject.org/updates/selinux-policy-3.10.0-161.fc17
Package selinux-policy-3.10.0-161.fc17: * should fix your issue, * was pushed to the Fedora 17 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=updates-testing selinux-policy-3.10.0-161.fc17' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/FEDORA-2012-18787/selinux-policy-3.10.0-161.fc17 then log in and leave karma (feedback).
selinux-policy-3.10.0-161.fc17 has been pushed to the Fedora 17 stable repository. If problems still persist, please make note of it in this bug report.