LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Desktop
User Name
Password
Linux - Desktop This forum is for the discussion of all Linux Software used in a desktop context.

Notices


Reply
  Search this Thread
Old 01-22-2022, 04:00 AM   #1
yabobay
Member
 
Registered: Jul 2019
Distribution: Debian Sid
Posts: 44

Rep: Reputation: Disabled
SELinux complains about tumblerd wanting write access the sock_file bus


I recently installed Fedora 35 with Xfce and am running into occasional SELinux notifications complaining about this problem:

Code:
SELinux is preventing tumblerd from write access on the sock_file bus.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that tumblerd should be allowed write access on the bus sock_file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'tumblerd' --raw | audit2allow -M my-tumblerd
# semodule -X 300 -i my-tumblerd.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                unconfined_u:object_r:session_dbusd_tmp_t:s0
Target Objects                bus [ sock_file ]
Source                        tumblerd
Source Path                   tumblerd
Port                          <Unknown>
Host                          fedora
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-35.10-1.fc35.noarch
Local Policy RPM              selinux-policy-targeted-35.10-1.fc35.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     fedora
Platform                      Linux fedora 5.15.14-200.fc35.x86_64 #1 SMP Tue
                              Jan 11 16:49:27 UTC 2022 x86_64 x86_64
Alert Count                   104
First Seen                    2022-01-20 20:39:27 EET
Last Seen                     2022-01-22 11:41:37 EET
Local ID                      6dee6fdc-076e-437c-952e-b6b5d3f55760

Raw Audit Messages
type=AVC msg=audit(1642844497.194:323): avc:  denied  { write } for  pid=4987 comm="tumblerd" name="bus" dev="tmpfs" ino=46 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:session_dbusd_tmp_t:s0 tclass=sock_file permissive=0


Hash: tumblerd,thumb_t,session_dbusd_tmp_t,sock_file,write
Thanks SELinux, very useful.

I want to do as instructed here and run those commands, but I'm hesitant since i don't know what the problem really is, or what this fix actually does.
 
Old 01-22-2022, 05:39 AM   #2
shruggy
Senior Member
 
Registered: Mar 2020
Posts: 3,678

Rep: Reputation: Disabled
The fix was committed to selinux-policy Git repo yesterday. It will appear in Rawhide soon, then in F35 as well. The relevant bug is rhbz#2042696.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] Oddity with tumblerd business_kid Slackware 11 05-12-2014 03:20 AM
Tumblerd interferes with removable media Slackovado Slackware 6 12-27-2012 05:08 AM
Dbus System bus and Session bus mainloops deimus Linux - Distributions 0 08-20-2010 06:49 AM
Wanting to write board game keiththib Programming 1 11-27-2009 05:31 AM
About SElinux: enter "setenforce 0",system complains bad command aladin Linux - Software 3 08-21-2005 08:16 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Desktop

All times are GMT -5. The time now is 06:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration