denied {search} pam_console_app

Robin Bowes robin-lists at robinbowes.com
Mon Nov 6 12:07:26 UTC 2006


Hi,

I'm seeing a whole raft of these msgs at boot:

audit(1162812576.696:158): avc:  denied  { search } for  pid=523
comm="pam_console_app" name="var" dev=dm-0 ino=229377
scontext=system_u:system_r:pam_console_t:s0-s0:c0.c255
tcontext=system_u:object_r:file_t:s0 tclass=dir

audit2allow suggests this to fix:

allow pam_console_t file_t:dir search;

My question:

Is this the right fix? Or is there some chcon magic I can do?

R.




More information about the fedora-selinux-list mailing list