gconf AVCs....

Tom London selinux at gmail.com
Fri Jul 20 14:22:09 UTC 2007


Login spawns these:

type=USER_LOGIN msg=audit(1184940747.700:30): user pid=3063 uid=0
auid=500 subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 msg='uid=500:
exe="/usr/sbin/gdm-binary" (hostname=localhost.localdomain,
addr=127.0.0.1, terminal=:0 res=success)'
type=AVC msg=audit(1184940749.700:31): avc:  denied  { associate } for
 pid=3234 comm="gconfd-2" name=".testing.writeability"
scontext=system_u:object_r:unlabeled_t:s0
tcontext=system_u:object_r:fs_t:s0 tclass=filesystem
type=SYSCALL msg=audit(1184940749.700:31): arch=40000003 syscall=5
success=no exit=-13 a0=811ef20 a1=41 a2=1c0 a3=811ef20 items=0 ppid=1
pid=3234 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500
sgid=500 fsgid=500 tty=(none) comm="gconfd-2"
exe="/usr/libexec/gconfd-2" subj=system_u:system_r:unconfined_t:s0
key=(null)
type=AVC msg=audit(1184940756.200:32): avc:  denied  { associate } for
 pid=3234 comm="gconfd-2" name=".testing.writeability"
scontext=system_u:object_r:unlabeled_t:s0
tcontext=system_u:object_r:fs_t:s0 tclass=filesystem
type=SYSCALL msg=audit(1184940756.200:32): arch=40000003 syscall=5
success=no exit=-13 a0=8345d90 a1=41 a2=1c0 a3=8345d90 items=0 ppid=1
pid=3234 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500
sgid=500 fsgid=500 tty=(none) comm="gconfd-2"
exe="/usr/libexec/gconfd-2" subj=system_u:system_r:unconfined_t:s0
key=(null)
type=AVC msg=audit(1184940779.699:33): avc:  denied  { associate } for
 pid=3234 comm="gconfd-2" name="saved_state.tmp"
scontext=system_u:object_r:unlabeled_t:s0
tcontext=system_u:object_r:fs_t:s0 tclass=filesystem
type=SYSCALL msg=audit(1184940779.699:33): arch=40000003 syscall=5
success=no exit=-13 a0=834c8a0 a1=241 a2=1c0 a3=811d230 items=0 ppid=1
pid=3234 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500
sgid=500 fsgid=500 tty=(none) comm="gconfd-2"
exe="/usr/libexec/gconfd-2" subj=system_u:system_r:unconfined_t:s0
key=(null)

tom
-- 
Tom London




More information about the fedora-selinux-list mailing list