selinux-refpolicy.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* strange systemd audit message
@ 2019-01-30 13:02 Russell Coker
  2019-01-30 23:42 ` Chris PeBenito
  0 siblings, 1 reply; 3+ messages in thread
From: Russell Coker @ 2019-01-30 13:02 UTC (permalink / raw)
  To: selinux-refpolicy

I'm seeing the following every time I login as sysadm_r, whether it's via /
bin/login or sshd.  But the login works correctly anyway.  Any suggestions for 
what I should investigate?

type=PROCTITLE msg=audit(30/01/19 23:58:01.196:1595535) : proctitle=(systemd) 
type=SYSCALL msg=audit(30/01/19 23:58:01.196:1595535) : arch=x86_64 
syscall=execve success=no exit=EACCES(Permission denied) a0=0x55f2c3008780 
a1=0x55f2c2fbe740 a2=0x55f2c302f1e0 a3=0x55f2c2e06010 items=0 ppid=1 pid=19802 
auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root 
fsgid=root tty=(none) ses=189 comm=(systemd) exe=/lib/systemd/systemd 
subj=system_u:system_r:init_t:s0 key=(null) 
type=AVC msg=audit(30/01/19 23:58:01.196:1595535) : avc:  denied  { transition 
} for  pid=19802 comm=(systemd) path=/lib/systemd/systemd dev="dm-0" 
ino=3069920 scontext=system_u:system_r:init_t:s0 
tcontext=root:sysadm_r:sysadm_t:s0 tclass=process permissive=0

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/




^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-01-31  7:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-01-30 13:02 strange systemd audit message Russell Coker
2019-01-30 23:42 ` Chris PeBenito
2019-01-31  7:53   ` Dominick Grift

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).