Research Menu

.
Skip Search Box

SELinux Mailing List

Question - dac_override/dac_read_search

From: Ivan Gyurdiev <ivg2_at_cornell.edu>
Date: Fri, 04 Mar 2005 05:19:07 -0500


I've seen these before, and here they are again. What causes those denials, and how can I fix them in general?

This specific case is running depmod -a as root.

audit(1109930761.807:0): avc: denied { dac_override } for pid=4678 exe=/sbin/depmod capability=1 scontext=root:sysadm_r:depmod_t tcontext=root:sysadm_r:depmod_t tclass=capability

audit(1109930761.807:0): avc: denied { dac_read_search } for pid=4678 exe=/sbin/depmod capability=2 scontext=root:sysadm_r:depmod_t tcontext=root:sysadm_r:depmod_t tclass=capability

--

Ivan Gyurdiev <ivg2@cornell.edu>
Cornell University

--

This message was distributed to subscribers of the selinux mailing list. If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with the words "unsubscribe selinux" without quotes as the message. Received on Fri 4 Mar 2005 - 05:19:18 EST

 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service