View Issue Details

IDProjectCategoryView StatusLast Update
0016082CentOS-7selinux-policypublic2019-05-14 15:14
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
PlatformOSOS Version7
Product Version 
Target VersionFixed in Version 
Summary0016082: SELinux is preventing /opt/phantomjs/bin/phantomjs from 'execute' accesses on the archivo /etc/
DescriptionDescription of problem:
SELinux is preventing /opt/phantomjs/bin/phantomjs from 'execute' accesses on the archivo /etc/

***** Plugin restorecon_source (99.5 confidence) suggests *****************

Si quiere corregir la etiqueta.
La etiqueta predeterminada de /opt/phantomjs/bin/phantomjs debería ser bin_t.
Then puede ejecutar restorecon.
# /sbin/restorecon -v /opt/phantomjs/bin/phantomjs

***** Plugin catchall (1.49 confidence) suggests **************************

Si cree que de manera predeterminada se debería permitir a phantomjs el acceso execute sobre file.
Then debería reportar esto como un error.
Puede generar un módulo de política local para permitir este acceso.
permita el acceso temporalmente ejecutando:
# ausearch -c 'phantomjs' --raw | audit2allow -M mi-phantomjs
# semodule -i mi-phantomjs.pp

Additional Information:
Source Context system_u:system_r:httpd_t:s0
Target Context unconfined_u:object_r:ld_so_cache_t:s0
Target Objects /etc/ [ file ]
Source phantomjs
Source Path /opt/phantomjs/bin/phantomjs
Port <Unknown>
Host (removed)
Source RPM Packages
Target RPM Packages glibc-2.17-260.el7_6.5.x86_64
Policy RPM selinux-policy-3.13.1-229.el7_6.12.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Permissive
Host Name (removed)
Platform Linux (removed) 3.10.0-957.12.1.el7.x86_64 #1 SMP
                              Mon Apr 29 14:59:59 UTC 2019 x86_64 x86_64
Alert Count 8
First Seen 2019-05-14 16:54:54 CEST
Last Seen 2019-05-14 17:10:02 CEST
Local ID d18ff5ee-0349-4aff-ae6b-e9e3ffb58174

Raw Audit Messages
type=AVC msg=audit(1557846602.465:907): avc: denied { execute } for pid=13279 comm="phantomjs" path="/etc/" dev="dm-0" ino=67470459 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:ld_so_cache_t:s0 tclass=file permissive=1

Hash: phantomjs,httpd_t,ld_so_cache_t,file,execute

Version-Release number of selected component:
Additional Informationreporter: libreport-
hashmarkername: setroubleshoot
kernel: 3.10.0-957.12.1.el7.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.


There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2019-05-14 15:14 GoodWolf8 New Issue