Summary:
SELinux is preventing gdm-simple-gree (xdm_t) "search" httpd_sys_content_t.
Detailed Description:
SELinux denied access requested by gdm-simple-gree. It is not expected that this
access is required by gdm-simple-gree and this access may signal an intrusion
attempt. It is also possible that the specific version or configuration of the
application is causing it to require additional access.
Allowing Access:
You can generate a local policy module to allow this access - see FAQ
(
http://fedora.redhat.com/docs/selinu...fc5/#id2961385) Or you can disable
SELinux protection altogether. Disabling SELinux protection is not recommended.
Please file a bug report (
http://bugzilla.redhat.com/bugzilla/enter_bug.cgi)
against this package.
Additional Information:
Source Context system_u:system_r:xdm_t:s0-s0:c0.c1023
Target Context system_u

bject_r:httpd_sys_content_t:s0
Target Objects www [ dir ]
Source gdm-simple-gree
Source Path /usr/libexec/gdm-simple-greeter
Port <Unknown>
Host mail.[xyz].net
Source RPM Packages gdm-2.26.1-10.fc11
Target RPM Packages
Policy RPM selinux-policy-3.6.12-39.fc11
Selinux Enabled True
Policy Type targeted
MLS Enabled True
Enforcing Mode Enforcing
Plugin Name catchall
Host Name mail.[xyz].net
Platform Linux mail.[xyz].net 2.6.29.4-167.fc11.x86_64 #1
SMP Wed May 27 17:27:08 EDT 2009 x86_64 x86_64
Alert Count 1497
First Seen Fri Nov 26 15:17:30 2010
Last Seen Fri Nov 26 16:57:08 2010
Local ID f8cd1f18-a337-49b9-9df0-209683dfe750
Line Numbers
Raw Audit Messages
node=mail.[xyz].net type=AVC msg=audit(1290761828.686:613042): avc: denied { search } for pid=2779 comm="gdm-simple-gree" name="www" dev=dm-0 ino=35668 scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u

bject_r:httpd_sys_content_t:s0 tclass=dir
node=mail.[xyz].net type=SYSCALL msg=audit(1290761828.686:613042): arch=c000003e syscall=254 success=no exit=-13 a0=12 a1=17e0e10 a2=1002fce a3=1 items=0 ppid=2753 pid=2779 auid=4294967295 uid=42 gid=42 euid=42 suid=42 fsuid=42 egid=42 sgid=42 fsgid=42 tty=(none) ses=4294967295 comm="gdm-simple-gree" exe="/usr/libexec/gdm-simple-greeter" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)