# Get selinux SELinux is preventing /usr/libexec/geoclue from name\_bind access on the udp\_socket port 960

**URL:** <https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-8\
**Created:** [October 12, 2024, 4:09am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174 "2024-10-12T04:09:31Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 12, 2024, 4:09am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/1 "2024-10-12T04:09:31Z")

</div>

I config the rocky linux 8 as a NIS Client and NFS Client of mounting /home/$USER directories. The NIS works propoerly. The NFS mount directories propoerly and access as normal. But every time I restart the rocky linux 8, I get selinux message about:

```auto
SELinux is preventing /usr/libexec/geoclue from name_bind access on the udp_socket port 960.
If you believe that geoclue should be allowed name_bind access on the port 960 udp_socket by default.
You should report this as a bug. You can generate a local policy module to allow this access.

type=AVC msg=audit(1728705440.476:567): avc: denied { name_bind } for pid=13928 comm="pool" src=960 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
type=SYSCALL msg=audit(1728705440.476:567): arch=c000003e syscall=49 success=no exit=-13 a0=b a1=7fa03affbd00 a2=10 a3=7fa03affbd1c items=0 ppid=1 pid=13928 auid=4294967295 uid=995 gid=992 euid=995 suid=995 fsuid=995 egid=992 sgid=992 fsgid=992 tty=(none) ses=4294967295 comm="pool" exe="/usr/libexec/geoclue" subj=system_u:system_r:geoclue_t:s0 key=(null)

```

And the port will change after each restart. How to fix this? I do not want to disable selinux for safety reason.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [October 12, 2024, 9:09am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/2 "2024-10-12T09:09:00Z")

</div>

You can install this package:

```auto
dnf install policycoreutils-python-utils

```

and then once installed, use the following commands to see what explanation it gives from parsing `/var/log/audit/audit.log`

```auto
audit2why -a

```

and:

```auto
audit2allow -a

```

once you’ve seen the results from these, then we can get an idea of what needs to be done next to allow it to bind on that port, etc.

---

<div class="post-metadata">

**Author:** ![gerry666uk](https://avatars.discourse-cdn.com/v4/letter/g/dbc845/32.png) [@gerry666uk](https://forums.rockylinux.org/u/gerry666uk)\
**Post date:** [October 12, 2024, 3:43pm UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/3 "2024-10-12T15:43:29Z")

</div>

Info about goeclue

```auto
rpm -q geoclue2
geoclue2-2.6.0-7.el9.x86_64

```

it’s a “geo location” service, e.g. you have a weather app and it knows which ciry you are in.

The first question I’d ask is why it’s trying to bind to udf port 960? Maybe there’s a good reason, but selinux is being careful.

I don’ t think this message happens on default install of Rocky 9.4.

---

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 14, 2024, 2:03am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/4 "2024-10-14T02:03:17Z")

</div>

Thank you for your help~  
After I execute `audit2why -a` , I got the following output

```auto
type=AVC msg=audit(1728668834.710:362): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728668834.711:363): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728669237.231:538): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728669237.232:539): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704673.392:9310): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704673.393:9311): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704750.116:9363): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704750.117:9364): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704862.725:9412): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728704862.726:9413): avc: denied { name_bind } for pid=14397 comm="pool" src=1005 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728705158.353:350): avc: denied { name_bind } for pid=13928 comm="pool" src=960 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728705158.354:351): avc: denied { name_bind } for pid=13928 comm="pool" src=960 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728705440.476:566): avc: denied { name_bind } for pid=13928 comm="pool" src=960 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728705440.476:567): avc: denied { name_bind } for pid=13928 comm="pool" src=960 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728706596.069:337): avc: denied { name_bind } for pid=15404 comm="pool" src=740 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728706596.070:338): avc: denied { name_bind } for pid=15404 comm="pool" src=740 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:hi_reserved_port_t:s0 tclass=udp_socket permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728799186.648:25068): avc: denied { unlink } for pid=2494955 comm="systemd-user-ru" name="1393" dev="tmpfs" ino=13547767 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=unconfined_u:object_r:session_dbusd_tmp_t:s0 tclass=file permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

type=AVC msg=audit(1728799186.648:25069): avc: denied { unlink } for pid=2494955 comm="systemd-user-ru" name="43" dev="tmpfs" ino=45849 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=unconfined_u:object_r:session_dbusd_tmp_t:s0 tclass=file permissive=0
        Was caused by:
                Missing type enforcement (TE) allow rule.

                You can use audit2allow to generate a loadable module to allow this access.

```

And after I execute `audit2allow -a`, I got:

```auto
#============= geoclue_t ==============
allow geoclue_t hi_reserved_port_t:udp_socket name_bind;

#============= systemd_logind_t ==============
allow systemd_logind_t session_dbusd_tmp_t:file unlink;

```

Is there any problem with the geoclue or the rpb bind?  
Looking for your reply.  
Best wishes

---

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 14, 2024, 2:07am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/5 "2024-10-14T02:07:47Z")

</div>

Thank you for your reply~  
In my system, I use rocky linux 8.10, and my info about goeclue is:

```auto
geoclue2-2.5.5-2.el8.x86_64

```

This problem happens after I setting NFS Client to mount home directory of each users, and somtimes happend after I mount other NFS directorys. I use NIS to implement the auth.  
Is there any information you need to help me solve this problem?  
Looking forward to your kindly reply.  
Best wishes

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [October 14, 2024, 7:11am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/6 "2024-10-14T07:11:26Z")

</div>

Normally if audit2why says about generating a loadable module, when we use audit2allow it should also give commands on how to generate that module. However, your audit2allow output doesn’t show that, so I don’t know if you didn’t copy all the information from the output, or it’s not showing it for some reason.

---

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 14, 2024, 8:02am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/7 "2024-10-14T08:02:34Z")

</div>

I am sure that this is the all output information. Could you help me to find the reason why it’s not showing the commands on how to generate that module?

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [October 14, 2024, 8:14am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/8 "2024-10-14T08:14:53Z")

</div>

You can try this:

```auto
grep geoclue /var/log/audit/audit.log | audit2allow -M geoclue
semodule -i geoclue.pp

```

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [October 14, 2024, 8:30am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/9 "2024-10-14T08:30:23Z")

</div>

There are, by default, some events that are not logged. The “dontaudit” events.  
See `man semanage-dontaudit` and [Chapter&nbsp;5.&nbsp;Troubleshooting problems related to SELinux | Red Hat Product Documentation](https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/using_selinux/troubleshooting-problems-related-to-selinux_using-selinux#troubleshooting-problems-related-to-selinux_using-selinux)

Alas, if your denied accesses were such, then audit2why could not list them, since they would not be in the log.

---

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 14, 2024, 11:57am UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/10 "2024-10-14T11:57:35Z")

</div>

Thank your for your kindly reply~

> [@iwalker](#):
>
> `grep geoclue /var/log/audit/audit.log | audit2allow -M geoclue`

When I execute `grep geoclue /var/log/audit/audit.log | audit2allow -M geoclue`, I got

```auto
[root@thehost ~]# grep geoclue /var/log/audit/audit.log | audit2allow -M geoclue
Nothing to do

```

Is this correct?  
Best Regards

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [October 14, 2024, 12:08pm UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/11 "2024-10-14T12:08:45Z")

</div>

Looks like there is no violation to fix, it was just something to try to see. Obviously that will be why the audit2allow results didn’t suggest anything.

Therefore it doesn’t look like selinux is the problem here.

---

<div class="post-metadata">

**Author:** ![haoyahao3](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/haoyahao3/32/4840_2.png) [@haoyahao3](https://forums.rockylinux.org/u/haoyahao3)\
**Post date:** [October 14, 2024, 12:39pm UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/12 "2024-10-14T12:39:30Z")

</div>

Thank you for your reply~  
After I set dontaudit, I got many selinux messages about the name bind:

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/6/6e938ca9b3afcf8a0ee52744cac955f54b67a053.png)  
Is there any help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [December 13, 2024, 12:39pm UTC](https://forums.rockylinux.org/t/get-selinux-selinux-is-preventing-usr-libexec-geoclue-from-name-bind-access-on-the-udp-socket-port-960/16174/13 "2024-12-13T12:39:57Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
