View Issue Details

IDProjectCategoryView StatusLast Update
0017150CentOS-7selinux-policypublic2020-03-15 00:45
Reporterawsmtek Assigned To 
PrioritynormalSeverityminorReproducibilityhave not tried
Status newResolutionopen 
OS Version7 
Summary0017150: SELinux is preventing /usr/sbin/pcscd from read, write access on the file
DescriptionDescription of problem:
sudo pcscd
sudo service pcscd stop
sudo service pcscd start
SELinux is preventing /usr/sbin/pcscd from read, write access on the file

***** Plugin catchall (100. confidence) suggests **************************

If you believe that pcscd should be allowed read write access on the file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
allow this access for now by executing:
# ausearch -c 'pcscd' --raw | audit2allow -M my-pcscd
# semodule -i my-pcscd.pp

Additional Information:
Source Context system_u:system_r:pcscd_t:s0
Target Context unconfined_u:object_r:var_run_t:s0
Target Objects [ file ]
Source pcscd
Source Path /usr/sbin/pcscd
Port <Unknown>
Host (removed)
Source RPM Packages pcsc-lite-1.8.8-8.el7.x86_64
Target RPM Packages
Policy RPM selinux-policy-3.13.1-252.el7.noarch
Selinux Enabled True
Policy Type targeted
Enforcing Mode Enforcing
Host Name (removed)
Platform Linux (removed) 3.10.0-1062.el7.x86_64 #1 SMP Wed
                              Aug 7 18:08:02 UTC 2019 x86_64 x86_64
Alert Count 1
First Seen 2020-03-15 03:37:07 MSK
Last Seen 2020-03-15 03:37:07 MSK
Local ID bd5fdf67-9ae7-44be-9f88-1ea4fc4c3fdf

Raw Audit Messages
type=AVC msg=audit(1584232627.869:539): avc: denied { read write } for pid=14043 comm="pcscd" name="" dev="tmpfs" ino=135639 scontext=system_u:system_r:pcscd_t:s0 tcontext=unconfined_u:object_r:var_run_t:s0 tclass=file permissive=0

type=SYSCALL msg=audit(1584232627.869:539): arch=x86_64 syscall=open success=no exit=EACCES a0=55a020048c84 a1=42 a2=1a4 a3=76 items=0 ppid=1 pid=14043 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=pcscd exe=/usr/sbin/pcscd subj=system_u:system_r:pcscd_t:s0 key=(null)

Hash: pcscd,pcscd_t,var_run_t,file,read,write

Version-Release number of selected component:
Additional Informationreporter: libreport-
hashmarkername: setroubleshoot
kernel: 3.10.0-1062.el7.x86_64
reproducible: Not sure how to reproduce the problem
type: libreport
TagsNo tags attached.


There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2020-03-15 00:45 awsmtek New Issue