What is "dac_override" AVC and how to troubleshoot it?

Solution Verified - Updated -

Issue

  • In the audit log I can see dac_override AVCs, e.g.

    type=PROCTITLE msg=... : proctitle=/usr/libexec/platform-python /usr/libexec/rhsmcertd-worker 
    type=SYSCALL msg=.... : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD ... auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=rhsmcertd-worke exe=/usr/libexec/platform-python3.6 subj=system_u:system_r:rhsmcertd_t:s0 key=(null) 
    type=AVC msg=... : avc:  denied  { dac_override } for  pid=... comm=rhsmcertd-worke capability=dac_override  scontext=system_u:system_r:rhsmcertd_t:s0 tcontext=system_u:system_r:rhsmcertd_t:s0 tclass=capability permissive=0 
    

Environment

  • Red Hat Enterprise Linux
    • SELinux

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content