FC3 " avc: denied" issue
Erwin J. Prinz
ejprinz at austin.rr.com
Sun Dec 26 01:18:41 UTC 2004
I have a fully upgraded (as of today) FC3 system on which I always could
install the NVIDIA drivers. But, to get a successful install after the
last upgrade (today) (which included selinux-policy-targeted.noarch
1.17.30-2.58) I now have to "setenforce 0" before installing the NVIDIA
drivers. Otherwise, the install fails due to several access denied
issues, e.g.:
Dec 25 18:51:34 tiger kernel: audit(1104022294.445:0): avc: denied {
write } for pid=3956 exe=/sbin/ldconfig
path=/var/log/nvidia-installer.log dev=hda6 ino=517383
scontext=root:system_r:ldconfig_t tcontext=system_u:object_r:var_log_t
tclass=file
Dec 25 18:51:34 tiger kernel: audit(1104022294.801:0): avc: denied {
read } for pid=3956 exe=/sbin/ldconfig name=libXvMCNVIDIA.so.1.0.6629
dev=hda4 ino=194830 scontext=root:system_r:ldconfig_t
tcontext=root:object_r:lib_t tclass=file
Dec 25 18:51:35 tiger kernel: audit(1104022295.012:0): avc: denied {
getattr } for pid=3956 exe=/sbin/ldconfig
path=/usr/X11R6/lib/libXvMCNVIDIA.so.1.0.6629 dev=hda4 ino=194830
scontext=root:system_r:ldconfig_t tcontext=root:object_r:lib_t tclass=file
Dec 25 18:51:38 tiger kernel: audit(1104022298.997:0): avc: denied {
getattr } for pid=3956 exe=/sbin/ldconfig
path=/usr/lib/libGL.so.1.0.6629 dev=hda4 ino=521611
scontext=root:system_r:ldconfig_t tcontext=root:object_r:lib_t
tclass=file/avc
The initial context of root is "root:system_r:unconfined_t" and I can't
change to "root:sysadm_r:sysadm_t". I did a "fixfiles relabel" and
reboot without changing the outcome.
I don't think the issue is with the NVIDIA drivers as they worked on FC3
before, and as "setenforce 0" "fixes" the issue.
I would appreciate pointers to what could be wrong.
Best regards, Erwin
More information about the fedora-selinux-list
mailing list