AVC on getpgid when executing "sudo reboot" as a user mapped to staff_u

Solution Verified - Updated -

Issue

  • After mapping staff_u SELinux user to a wheel user, this user can successfully execute sudo reboot but this generates AVC messages as per below:

    type=PROCTITLE msg=audit(...): proctitle=7375646F0062617368
    type=SYSCALL msg=audit(...): arch=c000003e syscall=121 success=no exit=-13 ... comm="sudo" exe="/usr/bin/sudo" subj=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 key=(null)
    type=AVC msg=audit(...): avc:  denied  { getpgid } for  ... comm="sudo" scontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tcontext=system_u:system_r:init_t:s0 tclass=process permissive=0
    

Environment

  • Red Hat Enterprise Linux 7 (RHEL7)
    • confined users mapped to staff_u

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content