SELinux is preventing access to files with the label, file_t error

Status
Not open for further replies.

ThinkFree

Technomancer
Got the following message(AVC denial) when I tried to upload a photo to picnik in FC10 64bit

Summary SELinux is preventing access to files with the label, file_t.
Detailed Description

SELinux permission checks on files labeled file_t are being denied. file_t is the context the SELinux kernel gives to files that do not have a label. This indicates a serious labeling problem. No files on an SELinux box should ever be labeled file_t. If you have just added a new disk drive to the system you can relabel it using the restorecon command. Otherwise you should relabel the entire files system.
Allowing Access
You can execute the following command as root to relabel your computer system: "touch /.autorelabel; reboot"
Additional Information
Source Context:**unconfined_u:unconfined_r:nsplugin_t:s0Target Context:**system_u:eek:bject_r:file_t:s0Target Objects:**/home/-------------/Desktop/_0471694665.zip [ file ]Source:**npviewer.binSource Path:**/usr/lib64/nspluginwrapper/npviewer.binPort:**<Unknown>Host:**localhost.localdomainSource RPM Packages:**nspluginwrapper-1.1.2-4.fc10Target RPM Packages:**Policy RPM:**selinux-policy-3.5.13-18.fc10Selinux Enabled:**TruePolicy Type:**targetedMLS Enabled:**TrueEnforcing Mode:**EnforcingPlugin Name:**fileHost Name:**localhost.localdomainPlatform:**Linux localhost.localdomain 2.6.27.9-159.fc10.x86_64 #1 SMP Tue Dec 16 14:47:52 EST 2008 x86_64 x86_64Alert Count:**2First Seen:**Wed 31 Dec 2008 04:37:35 PM ISTLast Seen:**Wed 31 Dec 2008 04:46:38 PM ISTLocal ID:**9e79e49d-0861-44f1-ac82-fe985f3f8492Line Numbers:**Raw Audit Messages :node=localhost.localdomain type=AVC msg=audit(1230722198.408:90): avc: denied { getattr } for pid=6677 comm="npviewer.bin" path="/home/----------/Desktop/_0471694665.zip" dev=sda5 ino=140093 scontext=unconfined_u:unconfined_r:nsplugin_t:s0 tcontext=system_u:eek:bject_r:file_t:s0 tclass=file node=localhost.localdomain type=SYSCALL msg=audit(1230722198.408:90): arch=c000003e syscall=6 success=no exit=-13 a0=1e90210 a1=7f8d88c43e00 a2=7f8d88c43e00 a3=1 items=0 ppid=2964 pid=6677 auid=500 uid=500 gid=500 euid=500 suid=500 fsuid=500 egid=500 sgid=500 fsgid=500 tty=(none) ses=1 comm="npviewer.bin" exe="/usr/lib64/nspluginwrapper/npviewer.bin" subj=unconfined_u:unconfined_r:nsplugin_t:s0 key=(null)

Can someone explain it?
 

mediator

Technomancer
I guess ur selinux is running in "enforcing" mode. I suggest u disable it if don't want to deal with the pain or run it in "permissive mode" if you want to passively learn it or keep it "enforced" if you wanna actively learn it.
Do what the troubleshooter says!
Allowing Access
You can execute the following command as root to relabel your computer system: "touch /.autorelabel; reboot"
*www.engardelinux.org/modules/index...t=fedora-selinux&page=0124.html&month=2008-02
*www.nabble.com/SELinux-is-preventing-access-to-files-with-the-label,-file_t.-td15815255.html
 

blondie

Broken In
If not running a server or some web service or a network, I recommend to disable or run in permissive mode on a normal web desktop. SELinux is always developing code and server testing is more regular than desktop.
 
Status
Not open for further replies.
Top Bottom