selinux is preveting to login after lightdm update

Bug #1605870 reported by Sebastien Chapuis
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Light Display Manager
Invalid
Undecided
Unassigned

Bug Description

Hello,
I just update lightdm from version 1.10.6 to 1.19.3 on my Fedora 24 Cinnamon.
When I try to login, I receive a message with selinux:

SELinux is preventing cinnamon-sessio from write access on the file .ICEauthority-c.

***** Plugin catchall (100. confidence) suggests **************************

If you believe that cinnamon-sessio should be allowed write access on the .ICEauthority-c file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'cinnamon-sessio' --raw | audit2allow -M my-cinnamonsessio
# semodule -X 300 -i my-cinnamonsessio.pp

Additional Information:
Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context system_u:object_r:iceauth_home_t:s0
Target Objects .ICEauthority-c [ file ]
Source cinnamon-sessio
Source Path cinnamon-sessio
Port <Unknown>
Host XPS13
Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.13.1-191.5.fc24.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name XPS13
Platform Linux XPS13 4.6.4-301.fc24.x86_64 #1 SMP Tue Jul
                              12 11:50:00 UTC 2016 x86_64 x86_64
Alert Count 78
First Seen 2016-07-21 01:26:55 CEST
Last Seen 2016-07-23 14:53:57 CEST
Local ID 3b219ff9-291f-458a-94e5-d209e7c65a99

Raw Audit Messages
type=AVC msg=audit(1469278437.587:204): avc: denied { write } for pid=1356 comm="cinnamon-sessio" name=".ICEauthority-c" dev="dm-0" ino=530399 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:object_r:iceauth_home_t:s0 tclass=file permissive=0

Hash: cinnamon-sessio,xdm_t,iceauth_home_t,file,write

Revision history for this message
Robert Ancell (robert-ancell) wrote :

LightDM doesn't provide any SELinux rules, I suspect the correct place to fix this issue is in the cinnamon-session package in Fedora.

Changed in lightdm:
status: New → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.