Skip to content

SELinux is preventing /usr/sbin/php-fpm from block_suspend access on the capability2 Unknown. #4

@ldim87

Description

@ldim87

SELinux is preventing /usr/sbin/php-fpm from block_suspend access on the
capability2 Unknown.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that php-fpm should be allowed block_suspend access on the
Unknown capability2 by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:

# ausearch -c 'php-fpm' --raw | audit2allow -M my-phpfpm
# semodule -i my-phpfpm.pp


Additional Information:
Source Context                system_u:system_r:httpd_t:s0
Target Context                system_u:system_r:httpd_t:s0
Target Objects                Unknown [ capability2 ]
Source                        php-fpm
Source Path                   /usr/sbin/php-fpm
Port                          <Unknown>
Host                          vwbe1
Source RPM Packages
Target RPM Packages
Policy RPM                    selinux-policy-3.13.1-102.el7_3.16.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     vwbe1
Platform                      Linux vwbe1 3.10.0-514.16.1.el7.x86_64 #1
                              SMP Wed Apr 12 15:04:24 UTC 2017 x86_64 x86_64
Alert Count                   10
First Seen                    2017-05-25 18:55:05 CEST
Last Seen                     2017-05-25 19:57:23 CEST
Local ID                      8143dd18-52d3-40b3-9f0b-587ebe308ad7

Raw Audit Messages
type=AVC msg=audit(1495735043.81:526): avc:  denied  { block_suspend } for 
pid=3530 comm="php-fpm" capability=36  scontext=system_u:system_r:httpd_t:s0
tcontext=system_u:system_r:httpd_t:s0 tclass=capability2


Hash: php-fpm,httpd_t,httpd_t,capability2,block_suspend

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions