AVC on getpgid when executing "sudo reboot" as a user mapped to staff_u
Issue
-
After mapping
staff_uSELinux user to a wheel user, this user can successfully executesudo rebootbut this generates AVC messages as per below:type=PROCTITLE msg=audit(...): proctitle=7375646F0062617368 type=SYSCALL msg=audit(...): arch=c000003e syscall=121 success=no exit=-13 ... comm="sudo" exe="/usr/bin/sudo" subj=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(...): avc: denied { getpgid } for ... comm="sudo" scontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tcontext=system_u:system_r:init_t:s0 tclass=process permissive=0
Environment
- Red Hat Enterprise Linux 7 (RHEL7)
- confined users mapped to
staff_u
- confined users mapped to
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.