Bug 1240604

Summary: SELinux is preventing /usr/bin/abrt-action-generate-core-backtrace from 'read' accesses on the file /var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri.
Product: [Fedora] Fedora Reporter: Vít Ondruch <vondruch>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED EOL QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 22CC: dominick.grift, dwalsh, jfilak, kibokin, lvrabec, mgrepl, plautrba
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
Whiteboard: abrt_hash:0d4b16fec1fe238c628f34fb2fb8a61368b1120a7b046f5c20704c0a55364440
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-07-19 15:14:25 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Vít Ondruch 2015-07-07 10:48:33 UTC
Description of problem:
Every time Ruby crashes inside of mock, I get this SELinux warning. Is there any chace to get this fixed?
SELinux is preventing /usr/bin/abrt-action-generate-core-backtrace from 'read' accesses on the file /var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri.

*****  Plugin restorecon (94.8 confidence) suggests   ************************

If you want to fix the label. 
/var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri default label should be mock_var_lib_t.
Then you can run restorecon.
Do
# /sbin/restorecon -v /var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri

*****  Plugin catchall_labels (5.21 confidence) suggests   *******************

If you want to allow abrt-action-generate-core-backtrace to have read access on the ruby-mri file
Then you need to change the label on /var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri
Do
# semanage fcontext -a -t FILE_TYPE '/var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri'
where FILE_TYPE is one of the following: NetworkManager_etc_rw_t, NetworkManager_etc_t, NetworkManager_exec_t, NetworkManager_initrc_exec_t, NetworkManager_tmp_t, abrt_dump_oops_exec_t, abrt_etc_t, abrt_exec_t, abrt_handle_event_exec_t, abrt_helper_exec_t, abrt_initrc_exec_t, abrt_retrace_coredump_exec_t, abrt_retrace_worker_exec_t, abrt_tmp_t, abrt_upload_watch_exec_t, abrt_upload_watch_tmp_t, abrt_var_cache_t, abrt_var_log_t, abrt_var_run_t, abrt_watch_log_exec_t, accountsd_exec_t, acct_exec_t, acct_initrc_exec_t, admin_crontab_tmp_t, admin_passwd_exec_t, afs_bosserver_exec_t, afs_cache_t, afs_exec_t, afs_fsserver_exec_t, afs_initrc_exec_t, afs_kaserver_exec_t, afs_ptserver_exec_t, afs_vlserver_exec_t, aiccu_etc_t, aiccu_exec_t, aiccu_initrc_exec_t, aide_exec_t, ajaxterm_exec_t, ajaxterm_initrc_exec_t, alsa_etc_rw_t, alsa_exec_t, alsa_tmp_t, amanda_exec_t, amanda_inetd_exec_t, amanda_recover_exec_t, amanda_tmp_t, amtu_exec_t, amtu_initrc_exec_t, anaconda_exec_t, anacron_exec_t, anon_inodefs_t, antivirus_conf_t, antivirus_exec_t, antivirus_initrc_exec_t, antivirus_tmp_t, apcupsd_cgi_script_exec_t, apcupsd_exec_t, apcupsd_initrc_exec_t, apcupsd_tmp_t, apm_exec_t, apmd_exec_t, apmd_initrc_exec_t, apmd_tmp_t, arpwatch_exec_t, arpwatch_initrc_exec_t, arpwatch_tmp_t, asterisk_etc_t, asterisk_exec_t, asterisk_initrc_exec_t, asterisk_tmp_t, audisp_exec_t, audisp_remote_exec_t, auditadm_sudo_tmp_t, auditctl_exec_t, auditd_exec_t, auditd_initrc_exec_t, authconfig_exec_t, autofs_t, automount_exec_t, automount_initrc_exec_t, automount_tmp_t, avahi_exec_t, avahi_initrc_exec_t, awstats_exec_t, awstats_script_exec_t, awstats_tmp_t, bacula_admin_exec_t, bacula_exec_t, bacula_initrc_exec_t, bacula_tmp_t, bacula_unconfined_script_exec_t, bcfg2_exec_t, bcfg2_initrc_exec_t, bin_t, bitlbee_conf_t, bitlbee_exec_t, bitlbee_initrc_exec_t, bitlbee_tmp_t, blktap_exec_t, blueman_exec_t, bluetooth_conf_t, bluetooth_exec_t, bluetooth_helper_exec_t, bluetooth_helper_tmp_t, bluetooth_helper_tmpfs_t, bluetooth_initrc_exec_t, bluetooth_tmp_t, boinc_exec_t, boinc_initrc_exec_t, boinc_project_tmp_t, boinc_tmp_t, boot_t, bootloader_etc_t, bootloader_exec_t, bootloader_tmp_t, brctl_exec_t, brltty_exec_t, bugzilla_script_exec_t, bugzilla_tmp_t, bumblebee_exec_t, cachefilesd_exec_t, calamaris_exec_t, callweaver_exec_t, callweaver_initrc_exec_t, canna_exec_t, canna_initrc_exec_t, cardctl_exec_t, cardmgr_dev_t, cardmgr_exec_t, ccs_exec_t, ccs_initrc_exec_t, ccs_tmp_t, cdcc_exec_t, cdcc_tmp_t, cdrecord_exec_t, cert_t, certmaster_exec_t, certmaster_initrc_exec_t, certmonger_exec_t, certmonger_initrc_exec_t, certmonger_unconfined_exec_t, certwatch_exec_t, cfengine_execd_exec_t, cfengine_initrc_exec_t, cfengine_monitord_exec_t, cfengine_serverd_exec_t, cgclear_exec_t, cgconfig_etc_t, cgconfig_exec_t, cgconfig_initrc_exec_t, cgred_exec_t, cgred_initrc_exec_t, cgrules_etc_t, checkpc_exec_t, checkpolicy_exec_t, chfn_exec_t, chkpwd_exec_t, chrome_sandbox_exec_t, chrome_sandbox_nacl_exec_t, chrome_sandbox_tmp_t, chronyd_exec_t, chronyd_initrc_exec_t, chroot_exec_t, cifs_t, cinder_api_exec_t, cinder_api_tmp_t, cinder_backup_exec_t, cinder_backup_tmp_t, cinder_scheduler_exec_t, cinder_scheduler_tmp_t, cinder_volume_exec_t, cinder_volume_tmp_t, ciped_exec_t, ciped_initrc_exec_t, clogd_exec_t, cloud_init_exec_t, cloud_init_tmp_t, cluster_conf_t, cluster_exec_t, cluster_initrc_exec_t, cluster_tmp_t, cluster_var_lib_t, cluster_var_run_t, clvmd_exec_t, clvmd_initrc_exec_t, cmirrord_exec_t, cmirrord_initrc_exec_t, cobbler_etc_t, cobbler_tmp_t, cobblerd_exec_t, cobblerd_initrc_exec_t, cockpit_session_exec_t, cockpit_tmp_t, cockpit_ws_exec_t, collectd_exec_t, collectd_initrc_exec_t, collectd_script_exec_t, collectd_script_tmp_t, colord_exec_t, colord_tmp_t, comsat_exec_t, comsat_tmp_t, condor_collector_exec_t, condor_conf_t, condor_initrc_exec_t, condor_master_exec_t, condor_master_tmp_t, condor_negotiator_exec_t, condor_procd_exec_t, condor_schedd_exec_t, condor_schedd_tmp_t, condor_startd_exec_t, condor_startd_tmp_t, conman_exec_t, conman_tmp_t, consolehelper_exec_t, consolekit_exec_t, couchdb_conf_t, couchdb_exec_t, couchdb_initrc_exec_t, couchdb_tmp_t, courier_authdaemon_exec_t, courier_etc_t, courier_exec_t, courier_pcp_exec_t, courier_pop_exec_t, courier_sqwebmail_exec_t, courier_tcpd_exec_t, cpu_online_t, cpucontrol_conf_t, cpucontrol_exec_t, cpufreqselector_exec_t, cpuplug_exec_t, cpuplug_initrc_exec_t, cpuspeed_exec_t, crack_exec_t, crack_tmp_t, crond_exec_t, crond_initrc_exec_t, crond_tmp_t, crontab_exec_t, crontab_tmp_t, ctdbd_exec_t, ctdbd_initrc_exec_t, ctdbd_tmp_t, cups_pdf_exec_t, cups_pdf_tmp_t, cupsd_config_exec_t, cupsd_etc_t, cupsd_exec_t, cupsd_initrc_exec_t, cupsd_lpd_exec_t, cupsd_lpd_tmp_t, cupsd_rw_etc_t, cupsd_tmp_t, cvs_exec_t, cvs_initrc_exec_t, cvs_script_exec_t, cvs_tmp_t, cyphesis_exec_t, cyphesis_initrc_exec_t, cyphesis_tmp_t, cyrus_exec_t, cyrus_initrc_exec_t, cyrus_tmp_t, dbadm_sudo_tmp_t, dbskkd_exec_t, dbskkd_tmp_t, dbusd_etc_t, dbusd_exec_t, dcc_client_exec_t, dcc_client_tmp_t, dcc_dbclean_exec_t, dcc_dbclean_tmp_t, dccd_exec_t, dccd_tmp_t, dccifd_exec_t, dccifd_tmp_t, dccm_exec_t, dccm_tmp_t, dcerpcd_exec_t, ddclient_etc_t, ddclient_exec_t, ddclient_initrc_exec_t, ddclient_tmp_t, debuginfo_exec_t, deltacloudd_exec_t, deltacloudd_tmp_t, denyhosts_exec_t, denyhosts_initrc_exec_t, depmod_exec_t, devicekit_disk_exec_t, devicekit_exec_t, devicekit_power_exec_t, devicekit_tmp_t, dhcp_etc_t, dhcpc_exec_t, dhcpc_helper_exec_t, dhcpc_tmp_t, dhcpd_exec_t, dhcpd_initrc_exec_t, dhcpd_tmp_t, dictd_etc_t, dictd_exec_t, dictd_initrc_exec_t, dirsrv_exec_t, dirsrv_snmp_exec_t, dirsrv_tmp_t, dirsrvadmin_exec_t, dirsrvadmin_script_exec_t, dirsrvadmin_tmp_t, dirsrvadmin_unconfined_script_exec_t, disk_munin_plugin_exec_t, disk_munin_plugin_tmp_t, dkim_milter_exec_t, dkim_milter_tmp_t, dlm_controld_exec_t, dlm_controld_initrc_exec_t, dmesg_exec_t, dmidecode_exec_t, dnsmasq_etc_t, dnsmasq_exec_t, dnsmasq_initrc_exec_t, dnssec_trigger_exec_t, docker_config_t, docker_exec_t, docker_share_t, docker_tmp_t, docker_var_lib_t, dosfs_t, dovecot_auth_exec_t, dovecot_auth_tmp_t, dovecot_deliver_exec_t, dovecot_deliver_tmp_t, dovecot_etc_t, dovecot_exec_t, dovecot_initrc_exec_t, dovecot_tmp_t, drbd_exec_t, drbd_initrc_exec_t, drbd_tmp_t, dspam_exec_t, dspam_initrc_exec_t, dspam_script_exec_t, ecryptfs_t, efivarfs_t, entropyd_exec_t, entropyd_initrc_exec_t, etc_mail_t, etc_runtime_t, etc_t, eventlogd_exec_t, evtchnd_exec_t, exim_exec_t, exim_initrc_exec_t, exim_tmp_t, exports_t, fail2ban_client_exec_t, fail2ban_exec_t, fail2ban_initrc_exec_t, fail2ban_tmp_t, fail2ban_var_lib_t, fcoemon_exec_t, fcoemon_initrc_exec_t, fenced_exec_t, fenced_tmp_t, fetchmail_etc_t, fetchmail_exec_t, fetchmail_initrc_exec_t, file_context_t, fingerd_etc_t, fingerd_exec_t, firewalld_etc_rw_t, firewalld_exec_t, firewalld_initrc_exec_t, firewalld_tmp_t, firewallgui_exec_t, firewallgui_tmp_t, firstboot_etc_t, firstboot_exec_t, foghorn_exec_t, foghorn_initrc_exec_t, fonts_cache_t, fonts_t, fprintd_exec_t, freeipmi_bmc_watchdog_exec_t, freeipmi_ipmidetectd_exec_t, freeipmi_ipmiseld_exec_t, freqset_exec_t, fsadm_exec_t, fsadm_tmp_t, fsdaemon_exec_t, fsdaemon_initrc_exec_t, fsdaemon_tmp_t, ftpd_etc_t, ftpd_exec_t, ftpd_initrc_exec_t, ftpd_tmp_t, ftpdctl_exec_t, ftpdctl_tmp_t, fusefs_t, fusermount_exec_t, games_exec_t, games_tmp_t, games_tmpfs_t, gconf_etc_t, gconf_tmp_t, gconfd_exec_t, gconfdefaultsm_exec_t, gdomap_conf_t, gdomap_exec_t, gdomap_initrc_exec_t, gear_exec_t, geoclue_exec_t, geoclue_tmp_t, getty_etc_t, getty_exec_t, getty_tmp_t, gfs_controld_exec_t, git_script_exec_t, git_script_tmp_t, gitd_exec_t, gitosis_exec_t, gkeyringd_exec_t, gkeyringd_tmp_t, glance_api_exec_t, glance_api_initrc_exec_t, glance_registry_exec_t, glance_registry_initrc_exec_t, glance_registry_tmp_t, glance_scrubber_exec_t, glance_scrubber_initrc_exec_t, glance_tmp_t, glusterd_exec_t, glusterd_initrc_exec_t, glusterd_tmp_t, gnomesystemmm_exec_t, gpg_agent_exec_t, gpg_agent_tmp_t, gpg_exec_t, gpg_helper_exec_t, gpg_pinentry_tmp_t, gpg_pinentry_tmpfs_t, gpm_conf_t, gpm_exec_t, gpm_initrc_exec_t, gpm_tmp_t, gpsd_exec_t, gpsd_initrc_exec_t, greylist_milter_exec_t, groupadd_exec_t, groupd_exec_t, gssd_exec_t, gssd_tmp_t, gssproxy_exec_t, haproxy_exec_t, hddtemp_etc_t, hddtemp_exec_t, hddtemp_initrc_exec_t, hostapd_exec_t, hostname_etc_t, hostname_exec_t, httpd_config_t, httpd_exec_t, httpd_helper_exec_t, httpd_initrc_exec_t, httpd_modules_t, httpd_passwd_exec_t, httpd_php_exec_t, httpd_php_tmp_t, httpd_rotatelogs_exec_t, httpd_suexec_exec_t, httpd_suexec_tmp_t, httpd_sys_content_t, httpd_sys_script_exec_t, httpd_tmp_t, httpd_unconfined_script_exec_t, httpd_user_script_exec_t, hwclock_exec_t, hypervkvp_exec_t, hypervkvp_initrc_exec_t, hypervvssd_exec_t, iceauth_exec_t, icecast_exec_t, icecast_initrc_exec_t, ifconfig_exec_t, inetd_child_exec_t, inetd_child_tmp_t, inetd_exec_t, inetd_tmp_t, init_exec_t, init_tmp_t, initrc_exec_t, initrc_tmp_t, initrc_var_run_t, innd_etc_t, innd_exec_t, innd_initrc_exec_t, insmod_exec_t, install_exec_t, iodined_exec_t, iodined_initrc_exec_t, iotop_exec_t, ipa_otpd_exec_t, ipsec_exec_t, ipsec_initrc_exec_t, ipsec_mgmt_exec_t, ipsec_tmp_t, iptables_exec_t, iptables_initrc_exec_t, iptables_tmp_t, irc_conf_t, irc_exec_t, irqbalance_exec_t, irqbalance_initrc_exec_t, irssi_etc_t, irssi_exec_t, iscsi_tmp_t, iscsid_exec_t, isnsd_exec_t, isnsd_initrc_exec_t, iso9660_t, iwhd_exec_t, iwhd_initrc_exec_t, jabberd_exec_t, jabberd_initrc_exec_t, jabberd_router_exec_t, jockey_exec_t, journalctl_exec_t, kadmind_exec_t, kadmind_tmp_t, kdump_crash_t, kdump_etc_t, kdump_exec_t, kdump_initrc_exec_t, kdumpctl_exec_t, kdumpctl_tmp_t, kdumpgui_exec_t, kdumpgui_tmp_t, keepalived_exec_t, keepalived_unconfined_script_exec_t, kerberos_initrc_exec_t, keyboardd_exec_t, keystone_cgi_script_exec_t, keystone_exec_t, keystone_initrc_exec_t, keystone_tmp_t, kismet_exec_t, kismet_initrc_exec_t, kismet_tmp_t, kismet_tmpfs_t, klogd_exec_t, klogd_tmp_t, kmscon_conf_t, kmscon_exec_t, kpropd_exec_t, krb5_conf_t, krb5_host_rcache_t, krb5kdc_conf_t, krb5kdc_exec_t, krb5kdc_tmp_t, ksmtuned_exec_t, ksmtuned_initrc_exec_t, ktalkd_exec_t, ktalkd_tmp_t, l2tp_conf_t, l2tpd_exec_t, l2tpd_initrc_exec_t, l2tpd_tmp_t, ld_so_cache_t, ld_so_t, ldconfig_exec_t, ldconfig_tmp_t, lib_t, likewise_etc_t, likewise_initrc_exec_t, lircd_etc_t, lircd_exec_t, lircd_initrc_exec_t, livecd_exec_t, livecd_tmp_t, lldpad_exec_t, lldpad_initrc_exec_t, load_policy_exec_t, loadkeys_exec_t, locale_t, locate_exec_t, lockdev_exec_t, login_exec_t, logrotate_exec_t, logrotate_mail_tmp_t, logrotate_tmp_t, logwatch_exec_t, logwatch_mail_tmp_t, logwatch_tmp_t, lpd_exec_t, lpd_tmp_t, lpr_exec_t, lpr_tmp_t, lsassd_exec_t, lsassd_tmp_t, lsmd_exec_t, lsmd_plugin_exec_t, lsmd_plugin_tmp_t, lvm_etc_t, lvm_exec_t, lvm_tmp_t, lwiod_exec_t, lwregd_exec_t, lwsmd_exec_t, machineid_t, mail_munin_plugin_exec_t, mail_munin_plugin_tmp_t, mailman_cgi_exec_t, mailman_cgi_tmp_t, mailman_mail_exec_t, mailman_mail_tmp_t, mailman_queue_exec_t, mailman_queue_tmp_t, man2html_script_exec_t, man_cache_t, man_t, mandb_cache_t, mandb_exec_t, mcelog_etc_t, mcelog_exec_t, mcelog_initrc_exec_t, mcelog_log_t, mdadm_conf_t, mdadm_exec_t, mdadm_initrc_exec_t, mediawiki_script_exec_t, mediawiki_tmp_t, memcached_exec_t, memcached_initrc_exec_t, mencoder_exec_t, minidlna_conf_t, minidlna_exec_t, minidlna_initrc_exec_t, minissdpd_conf_t, minissdpd_exec_t, minissdpd_initrc_exec_t, mip6d_exec_t, mock_build_exec_t, mock_etc_t, mock_exec_t, mock_tmp_t, mock_var_lib_t, modemmanager_exec_t, modules_conf_t, modules_object_t, mojomojo_script_exec_t, mojomojo_tmp_t, mon_procd_exec_t, mon_statd_exec_t, mon_statd_initrc_exec_t, mongod_exec_t, mongod_initrc_exec_t, mongod_tmp_t, motion_exec_t, mount_ecryptfs_exec_t, mount_exec_t, mount_tmp_t, mozilla_conf_t, mozilla_exec_t, mozilla_plugin_config_exec_t, mozilla_plugin_exec_t, mozilla_plugin_rw_t, mozilla_plugin_tmp_t, mozilla_plugin_tmpfs_t, mozilla_tmp_t, mozilla_tmpfs_t, mpd_etc_t, mpd_exec_t, mpd_initrc_exec_t, mpd_tmp_t, mplayer_etc_t, mplayer_exec_t, mplayer_tmpfs_t, mrtg_etc_t, mrtg_exec_t, mrtg_initrc_exec_t, mscan_etc_t, mscan_exec_t, mscan_initrc_exec_t, mscan_tmp_t, munin_etc_t, munin_exec_t, munin_initrc_exec_t, munin_script_exec_t, munin_script_tmp_t, munin_tmp_t, mysqld_etc_t, mysqld_exec_t, mysqld_initrc_exec_t, mysqld_safe_exec_t, mysqld_tmp_t, mysqlmanagerd_exec_t, mysqlmanagerd_initrc_exec_t, mythtv_script_exec_t, naemon_exec_t, naemon_initrc_exec_t, nagios_admin_plugin_exec_t, nagios_checkdisk_plugin_exec_t, nagios_etc_t, nagios_eventhandler_plugin_exec_t, nagios_eventhandler_plugin_tmp_t, nagios_exec_t, nagios_initrc_exec_t, nagios_mail_plugin_exec_t, nagios_openshift_plugin_exec_t, nagios_openshift_plugin_tmp_t, nagios_script_exec_t, nagios_services_plugin_exec_t, nagios_system_plugin_exec_t, nagios_system_plugin_tmp_t, nagios_tmp_t, nagios_unconfined_plugin_exec_t, named_checkconf_exec_t, named_conf_t, named_exec_t, named_initrc_exec_t, named_tmp_t, namespace_init_exec_t, ncftool_exec_t, ndc_exec_t, net_conf_t, netlabel_mgmt_exec_t, netlogond_exec_t, netutils_exec_t, netutils_tmp_t, neutron_exec_t, neutron_initrc_exec_t, neutron_tmp_t, newrole_exec_t, nfs_t, nfsd_exec_t, nfsd_initrc_exec_t, ninfod_exec_t, nis_initrc_exec_t, nmbd_exec_t, nova_ajax_exec_t, nova_ajax_tmp_t, nova_api_exec_t, nova_api_tmp_t, nova_cert_exec_t, nova_cert_tmp_t, nova_compute_exec_t, nova_compute_tmp_t, nova_conductor_exec_t, nova_conductor_tmp_t, nova_console_exec_t, nova_console_tmp_t, nova_direct_exec_t, nova_direct_tmp_t, nova_network_exec_t, nova_network_tmp_t, nova_objectstore_exec_t, nova_objectstore_tmp_t, nova_scheduler_exec_t, nova_scheduler_tmp_t, nova_vncproxy_exec_t, nova_vncproxy_tmp_t, nova_volume_exec_t, nova_volume_tmp_t, nrpe_etc_t, nrpe_exec_t, nscd_exec_t, nscd_initrc_exec_t, nsd_exec_t, nslcd_conf_t, nslcd_exec_t, nslcd_initrc_exec_t, ntop_etc_t, ntop_exec_t, ntop_initrc_exec_t, ntop_tmp_t, ntp_conf_t, ntpd_exec_t, ntpd_initrc_exec_t, ntpd_tmp_t, ntpdate_exec_t, numad_exec_t, nut_conf_t, nut_upsd_exec_t, nut_upsd_tmp_t, nut_upsdrvctl_exec_t, nut_upsdrvctl_tmp_t, nut_upsmon_exec_t, nut_upsmon_tmp_t, nutups_cgi_script_exec_t, nx_server_exec_t, nx_server_tmp_t, obex_exec_t, oddjob_exec_t, oddjob_mkhomedir_exec_t, openct_exec_t, openct_initrc_exec_t, openhpid_exec_t, openhpid_initrc_exec_t, openshift_cgroup_read_exec_t, openshift_cgroup_read_tmp_t, openshift_cron_exec_t, openshift_cron_tmp_t, openshift_initrc_exec_t, openshift_initrc_tmp_t, openshift_net_read_exec_t, openshift_script_exec_t, openshift_tmp_t, opensm_exec_t, openvpn_etc_rw_t, openvpn_etc_t, openvpn_exec_t, openvpn_initrc_exec_t, openvpn_tmp_t, openvpn_unconfined_script_exec_t, openvswitch_exec_t, openvswitch_rw_t, openvswitch_tmp_t, openwsman_exec_t, openwsman_tmp_t, oracleasm_exec_t, oracleasm_initrc_exec_t, osad_exec_t, osad_initrc_exec_t, pads_config_t, pads_exec_t, pads_initrc_exec_t, pam_console_exec_t, pam_timestamp_exec_t, pam_timestamp_tmp_t, passenger_exec_t, passenger_tmp_t, passwd_exec_t, passwd_file_t, pcp_pmcd_exec_t, pcp_pmcd_initrc_exec_t, pcp_pmie_exec_t, pcp_pmie_initrc_exec_t, pcp_pmlogger_exec_t, pcp_pmlogger_initrc_exec_t, pcp_pmmgr_exec_t, pcp_pmmgr_initrc_exec_t, pcp_pmproxy_exec_t, pcp_pmproxy_initrc_exec_t, pcp_pmwebd_exec_t, pcp_pmwebd_initrc_exec_t, pcp_tmp_t, pcp_var_lib_t, pcscd_exec_t, pcscd_initrc_exec_t, pegasus_conf_t, pegasus_exec_t, pegasus_openlmi_account_exec_t, pegasus_openlmi_admin_exec_t, pegasus_openlmi_logicalfile_exec_t, pegasus_openlmi_services_exec_t, pegasus_openlmi_storage_exec_t, pegasus_openlmi_storage_tmp_t, pegasus_openlmi_system_exec_t, pegasus_openlmi_unconfined_exec_t, pegasus_tmp_t, pesign_exec_t, phc2sys_exec_t, pinentry_exec_t, ping_exec_t, pingd_etc_t, pingd_exec_t, pingd_initrc_exec_t, piranha_etc_rw_t, piranha_fos_exec_t, piranha_lvs_exec_t, piranha_pulse_exec_t, piranha_pulse_initrc_exec_t, piranha_web_conf_t, piranha_web_exec_t, piranha_web_tmp_t, pkcs_slotd_exec_t, pkcs_slotd_initrc_exec_t, pkcs_slotd_tmp_t, pki_ra_exec_t, pki_ra_script_exec_t, pki_tomcat_exec_t, pki_tomcat_tmp_t, pki_tps_exec_t, pki_tps_script_exec_t, plymouth_exec_t, plymouthd_exec_t, podsleuth_exec_t, podsleuth_tmp_t, podsleuth_tmpfs_t, policykit_auth_exec_t, policykit_exec_t, policykit_grant_exec_t, policykit_reload_t, policykit_resolve_exec_t, policykit_tmp_t, policykit_var_lib_t, polipo_etc_t, polipo_exec_t, polipo_initrc_exec_t, portmap_exec_t, portmap_helper_exec_t, portmap_initrc_exec_t, portmap_tmp_t, portreserve_etc_t, portreserve_exec_t, portreserve_initrc_exec_t, postfix_bounce_exec_t, postfix_bounce_tmp_t, postfix_cleanup_exec_t, postfix_cleanup_tmp_t, postfix_etc_t, postfix_exec_t, postfix_initrc_exec_t, postfix_local_exec_t, postfix_local_tmp_t, postfix_map_exec_t, postfix_map_tmp_t, postfix_master_exec_t, postfix_pickup_exec_t, postfix_pickup_tmp_t, postfix_pipe_exec_t, postfix_pipe_tmp_t, postfix_postdrop_exec_t, postfix_postdrop_t, postfix_postqueue_exec_t, postfix_qmgr_exec_t, postfix_qmgr_tmp_t, postfix_showq_exec_t, postfix_smtp_exec_t, postfix_smtp_tmp_t, postfix_smtpd_exec_t, postfix_smtpd_tmp_t, postfix_virtual_exec_t, postfix_virtual_tmp_t, postgresql_etc_t, postgresql_exec_t, postgresql_initrc_exec_t, postgresql_tmp_t, postgrey_etc_t, postgrey_exec_t, postgrey_initrc_exec_t, pppd_etc_t, pppd_exec_t, pppd_initrc_exec_t, pppd_tmp_t, pptp_exec_t, prelink_cron_system_exec_t, prelink_exec_t, prelink_tmp_t, prelude_audisp_exec_t, prelude_correlator_config_t, prelude_correlator_exec_t, prelude_exec_t, prelude_initrc_exec_t, prelude_lml_exec_t, prelude_lml_tmp_t, preupgrade_exec_t, prewikka_script_exec_t, printconf_t, privoxy_exec_t, privoxy_initrc_exec_t, proc_t, proc_xen_t, procmail_exec_t, procmail_tmp_t, prosody_exec_t, psad_etc_t, psad_exec_t, psad_initrc_exec_t, psad_tmp_t, ptal_etc_t, ptal_exec_t, ptchown_exec_t, ptp4l_exec_t, public_content_rw_t, public_content_t, publicfile_exec_t, pulseaudio_exec_t, pulseaudio_tmpfs_t, puppet_etc_t, puppet_tmp_t, puppet_var_lib_t, puppetagent_exec_t, puppetagent_initrc_exec_t, puppetca_exec_t, puppetmaster_exec_t, puppetmaster_initrc_exec_t, puppetmaster_tmp_t, pwauth_exec_t, pyicqt_exec_t, qdiskd_exec_t, qemu_dm_exec_t, qemu_exec_t, qmail_clean_exec_t, qmail_etc_t, qmail_inject_exec_t, qmail_local_exec_t, qmail_lspawn_exec_t, qmail_queue_exec_t, qmail_remote_exec_t, qmail_rspawn_exec_t, qmail_send_exec_t, qmail_smtpd_exec_t, qmail_splogger_exec_t, qmail_start_exec_t, qmail_tcp_env_exec_t, qpidd_exec_t, qpidd_initrc_exec_t, qpidd_tmp_t, quota_exec_t, quota_nld_exec_t, rabbitmq_exec_t, rabbitmq_initrc_exec_t, racoon_exec_t, racoon_tmp_t, radiusd_etc_t, radiusd_exec_t, radiusd_initrc_exec_t, radvd_etc_t, radvd_exec_t, radvd_initrc_exec_t, rasdaemon_exec_t, rdisc_exec_t, readahead_exec_t, realmd_exec_t, realmd_tmp_t, redis_exec_t, redis_initrc_exec_t, regex_milter_exec_t, removable_t, restorecond_exec_t, rhev_agentd_exec_t, rhev_agentd_tmp_t, rhgb_exec_t, rhnsd_conf_t, rhnsd_exec_t, rhnsd_initrc_exec_t, rhsmcertd_exec_t, rhsmcertd_initrc_exec_t, rhsmcertd_tmp_t, ricci_exec_t, ricci_initrc_exec_t, ricci_modcluster_exec_t, ricci_modclusterd_exec_t, ricci_modlog_exec_t, ricci_modrpm_exec_t, ricci_modservice_exec_t, ricci_modstorage_exec_t, ricci_tmp_t, rlogind_exec_t, rlogind_tmp_t, rngd_exec_t, rngd_initrc_exec_t, rolekit_exec_t, rolekit_tmp_t, roundup_exec_t, roundup_initrc_exec_t, rpcbind_exec_t, rpcbind_initrc_exec_t, rpcbind_tmp_t, rpcd_exec_t, rpcd_initrc_exec_t, rpm_exec_t, rpm_log_t, rpm_script_exec_t, rpm_script_tmp_t, rpm_tmp_t, rpm_var_cache_t, rpm_var_lib_t, rpm_var_run_t, rshd_exec_t, rssh_chroot_helper_exec_t, rssh_exec_t, rsync_etc_t, rsync_exec_t, rsync_tmp_t, rtas_errd_exec_t, rtas_errd_tmp_t, rtkit_daemon_exec_t, rtkit_daemon_initrc_exec_t, run_init_exec_t, rwho_exec_t, rwho_initrc_exec_t, samba_etc_t, samba_initrc_exec_t, samba_net_exec_t, samba_net_tmp_t, samba_unconfined_script_exec_t, samba_var_t, sambagui_exec_t, sandbox_exec_t, sanlock_exec_t, sanlock_initrc_exec_t, saslauthd_exec_t, saslauthd_initrc_exec_t, sblim_gatherd_exec_t, sblim_initrc_exec_t, sblim_reposd_exec_t, sblim_sfcbd_exec_t, sblim_tmp_t, screen_exec_t, secadm_sudo_tmp_t, sectool_tmp_t, sectoolm_exec_t, selinux_munin_plugin_exec_t, selinux_munin_plugin_tmp_t, semanage_exec_t, semanage_tmp_t, sendmail_exec_t, sendmail_initrc_exec_t, sendmail_tmp_t, sensord_exec_t, sensord_initrc_exec_t, services_munin_plugin_exec_t, services_munin_plugin_tmp_t, session_dbusd_tmp_t, setfiles_exec_t, setkey_exec_t, setrans_exec_t, setrans_initrc_exec_t, setroubleshoot_fixit_exec_t, setroubleshootd_exec_t, setsebool_exec_t, seunshare_exec_t, sge_execd_exec_t, sge_job_exec_t, sge_shepherd_exec_t, sge_tmp_t, shell_exec_t, shorewall_etc_t, shorewall_exec_t, shorewall_initrc_exec_t, shorewall_tmp_t, shorewall_var_lib_t, showmount_exec_t, slapd_etc_t, slapd_exec_t, slapd_initrc_exec_t, slapd_tmp_t, slpd_exec_t, slpd_initrc_exec_t, smbcontrol_exec_t, smbd_exec_t, smbd_tmp_t, smbmount_exec_t, smokeping_cgi_script_exec_t, smokeping_exec_t, smokeping_initrc_exec_t, smoltclient_exec_t, smoltclient_tmp_t, smsd_exec_t, smsd_initrc_exec_t, smsd_tmp_t, snapperd_conf_t, snapperd_exec_t, snmpd_exec_t, snmpd_initrc_exec_t, snort_etc_t, snort_exec_t, snort_initrc_exec_t, snort_tmp_t, sosreport_exec_t, sosreport_tmp_t, soundd_etc_t, soundd_exec_t, soundd_initrc_exec_t, soundd_tmp_t, spamass_milter_exec_t, spamc_exec_t, spamc_tmp_t, spamd_etc_t, spamd_exec_t, spamd_initrc_exec_t, spamd_tmp_t, spamd_update_exec_t, speech-dispatcher_exec_t, speech-dispatcher_tmp_t, squid_conf_t, squid_cron_exec_t, squid_exec_t, squid_initrc_exec_t, squid_script_exec_t, squid_tmp_t, squirrelmail_spool_t, src_t, srvsvcd_exec_t, ssh_agent_exec_t, ssh_agent_tmp_t, ssh_exec_t, ssh_keygen_exec_t, ssh_keygen_tmp_t, ssh_keysign_exec_t, ssh_tmpfs_t, sshd_exec_t, sshd_initrc_exec_t, sshd_keygen_exec_t, sssd_conf_t, sssd_exec_t, sssd_initrc_exec_t, sssd_public_t, sssd_selinux_manager_exec_t, sssd_var_lib_t, staff_sudo_tmp_t, stapserver_exec_t, stapserver_tmp_t, stunnel_etc_t, stunnel_exec_t, stunnel_tmp_t, su_exec_t, sudo_exec_t, sulogin_exec_t, svc_conf_t, svc_multilog_exec_t, svc_run_exec_t, svc_start_exec_t, svirt_sandbox_file_t, svirt_tmp_t, svnserve_exec_t, svnserve_initrc_exec_t, svnserve_tmp_t, swat_exec_t, swat_tmp_t, swift_exec_t, swift_tmp_t, sysadm_passwd_tmp_t, sysadm_sudo_tmp_t, sysfs_t, syslog_conf_t, syslogd_exec_t, syslogd_initrc_exec_t, syslogd_tmp_t, syslogd_var_run_t, sysstat_exec_t, sysstat_initrc_exec_t, system_conf_t, system_cronjob_tmp_t, system_cronjob_var_lib_t, system_db_t, system_dbusd_tmp_t, system_dbusd_var_lib_t, system_mail_tmp_t, system_map_t, system_munin_plugin_exec_t, system_munin_plugin_tmp_t, systemd_hostnamed_exec_t, systemd_localed_exec_t, systemd_logger_exec_t, systemd_logind_exec_t, systemd_networkd_exec_t, systemd_notify_exec_t, systemd_passwd_agent_exec_t, systemd_sysctl_exec_t, systemd_systemctl_exec_t, systemd_timedated_exec_t, systemd_tmpfiles_exec_t, sysv_t, tcpd_exec_t, tcpd_tmp_t, tcsd_exec_t, tcsd_initrc_exec_t, telepathy_gabble_exec_t, telepathy_gabble_tmp_t, telepathy_idle_exec_t, telepathy_idle_tmp_t, telepathy_logger_exec_t, telepathy_logger_tmp_t, telepathy_mission_control_exec_t, telepathy_mission_control_tmp_t, telepathy_msn_exec_t, telepathy_msn_tmp_t, telepathy_salut_exec_t, telepathy_salut_tmp_t, telepathy_sofiasip_exec_t, telepathy_sofiasip_tmp_t, telepathy_stream_engine_exec_t, telepathy_stream_engine_tmp_t, telepathy_sunshine_exec_t, telepathy_sunshine_tmp_t, telnetd_exec_t, telnetd_tmp_t, tetex_data_t, textrel_shlib_t, tftpd_etc_t, tftpd_exec_t, tgtd_exec_t, tgtd_initrc_exec_t, tgtd_tmp_t, thin_aeolus_configserver_exec_t, thin_exec_t, thumb_exec_t, thumb_tmp_t, timemaster_exec_t, tmp_t, tmpreaper_exec_t, tomcat_exec_t, tomcat_tmp_t, tor_etc_t, tor_exec_t, tor_initrc_exec_t, traceroute_exec_t, tuned_etc_t, tuned_exec_t, tuned_initrc_exec_t, tuned_rw_etc_t, tuned_tmp_t, tvtime_exec_t, tvtime_tmp_t, tvtime_tmpfs_t, udev_etc_t, udev_exec_t, udev_helper_exec_t, udev_tmp_t, udev_var_run_t, ulogd_etc_t, ulogd_exec_t, ulogd_initrc_exec_t, uml_exec_t, uml_switch_exec_t, uml_tmp_t, uml_tmpfs_t, unconfined_exec_t, unconfined_munin_plugin_exec_t, unconfined_munin_plugin_tmp_t, update_modules_exec_t, update_modules_tmp_t, updfstab_exec_t, updpwd_exec_t, usbfs_t, usbmodules_exec_t, usbmuxd_exec_t, user_cron_spool_t, user_fonts_t, user_mail_tmp_t, user_tmp_t, useradd_exec_t, userhelper_conf_t, userhelper_exec_t, usernetctl_exec_t, usr_t, utempter_exec_t, uucpd_exec_t, uucpd_initrc_exec_t, uucpd_tmp_t, uuidd_exec_t, uuidd_initrc_exec_t, uux_exec_t, var_lib_t, var_log_t, var_spool_t, varnishd_etc_t, varnishd_exec_t, varnishd_initrc_exec_t, varnishd_tmp_t, varnishlog_exec_t, varnishlog_initrc_exec_t, vdagent_exec_t, vdagentd_initrc_exec_t, vhostmd_exec_t, vhostmd_initrc_exec_t, virsh_exec_t, virt_bridgehelper_exec_t, virt_etc_t, virt_qemu_ga_exec_t, virt_qemu_ga_tmp_t, virt_qemu_ga_unconfined_exec_t, virt_qmf_exec_t, virt_tmp_t, virtd_exec_t, virtd_initrc_exec_t, virtd_lxc_exec_t, vlock_exec_t, vmblock_t, vmtools_exec_t, vmtools_helper_exec_t, vmtools_tmp_t, vmware_exec_t, vmware_host_exec_t, vmware_host_tmp_t, vmware_sys_conf_t, vmware_tmp_t, vmware_tmpfs_t, vnstat_exec_t, vnstatd_exec_t, vnstatd_initrc_exec_t, vpnc_exec_t, vpnc_tmp_t, vxfs_t, w3c_validator_script_exec_t, w3c_validator_tmp_t, watchdog_exec_t, watchdog_initrc_exec_t, watchdog_unconfined_exec_t, wdmd_exec_t, wdmd_initrc_exec_t, webadm_tmp_t, webalizer_etc_t, webalizer_exec_t, webalizer_script_exec_t, webalizer_tmp_t, winbind_exec_t, winbind_helper_exec_t, wine_exec_t, wireshark_exec_t, wireshark_tmp_t, wireshark_tmpfs_t, wpa_cli_exec_t, xauth_exec_t, xauth_tmp_t, xdm_etc_t, xdm_exec_t, xdm_rw_etc_t, xdm_unconfined_exec_t, xenconsoled_exec_t, xend_exec_t, xend_tmp_t, xenfs_t, xenstored_exec_t, xenstored_tmp_t, xserver_etc_t, xserver_exec_t, xserver_log_t, xserver_tmpfs_t, xsession_exec_t, ypbind_exec_t, ypbind_initrc_exec_t, ypbind_tmp_t, yppasswdd_exec_t, ypserv_conf_t, ypserv_exec_t, ypserv_tmp_t, ypxfr_exec_t, zabbix_agent_exec_t, zabbix_agent_initrc_exec_t, zabbix_exec_t, zabbix_initrc_exec_t, zabbix_script_exec_t, zabbix_tmp_t, zarafa_deliver_exec_t, zarafa_deliver_tmp_t, zarafa_etc_t, zarafa_gateway_exec_t, zarafa_ical_exec_t, zarafa_indexer_exec_t, zarafa_indexer_tmp_t, zarafa_monitor_exec_t, zarafa_server_exec_t, zarafa_server_tmp_t, zarafa_spooler_exec_t, zarafa_var_lib_t, zebra_conf_t, zebra_exec_t, zebra_initrc_exec_t, zebra_tmp_t, zoneminder_exec_t, zoneminder_initrc_exec_t, zoneminder_script_exec_t, zos_remote_exec_t. 
Then execute: 
restorecon -v '/var/lib/mock/fedora-rawhide-x86_64/root/usr/bin/ruby-mri'


*****  Plugin catchall (1.44 confidence) suggests   **************************

If you believe that abrt-action-generate-core-backtrace should be allowed read access on the ruby-mri file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# grep abrt-action-gen /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                system_u:system_r:abrt_t:s0-s0:c0.c1023
Target Context                unconfined_u:object_r:unlabeled_t:s0
Target Objects                /var/lib/mock/fedora-rawhide-x86_64/root/usr/bin
                              /ruby-mri [ file ]
Source                        abrt-action-gen
Source Path                   /usr/bin/abrt-action-generate-core-backtrace
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           abrt-addon-ccpp-2.6.0-1.fc22.x86_64
Target RPM Packages           
Policy RPM                    selinux-policy-3.13.1-128.2.fc22.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 4.0.6-300.fc22.x86_64 #1 SMP Tue
                              Jun 23 13:58:53 UTC 2015 x86_64 x86_64
Alert Count                   19
First Seen                    2015-06-24 16:09:40 CEST
Last Seen                     2015-07-07 12:46:34 CEST
Local ID                      4f004f19-ca0b-45f2-ad89-b7b999fe1f8b

Raw Audit Messages
type=AVC msg=audit(1436265994.941:2310): avc:  denied  { read } for  pid=24708 comm="abrt-action-gen" name="ruby-mri" dev="dm-10" ino=399092 scontext=system_u:system_r:abrt_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:unlabeled_t:s0 tclass=file permissive=0


type=SYSCALL msg=audit(1436265994.941:2310): arch=x86_64 syscall=open success=no exit=EACCES a0=7fb3c7dd7f70 a1=0 a2=7fb3c7dde9e0 a3=7fb3c7dde850 items=0 ppid=24704 pid=24708 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=abrt-action-gen exe=/usr/bin/abrt-action-generate-core-backtrace subj=system_u:system_r:abrt_t:s0-s0:c0.c1023 key=(null)

Hash: abrt-action-gen,abrt_t,unlabeled_t,file,read

Version-Release number of selected component:
selinux-policy-3.13.1-128.2.fc22.noarch

Additional info:
reporter:       libreport-2.6.0
hashmarkername: setroubleshoot
kernel:         4.0.6-300.fc22.x86_64
type:           libreport

Comment 1 Daniel Walsh 2015-07-07 12:51:45 UTC
Probably best if abrt did not look at mock content.

Might want to add a dontaudit rule for abrt to not look at unlabeled_t content.

Comment 2 Vít Ondruch 2015-07-07 12:54:47 UTC
(In reply to Daniel Walsh from comment #1)
> Probably best if abrt did not look at mock content.

Actually there was an idea, that ABRT would report crashes inside mock the same way as it does for regular system and I like this idea, but not sure how far it is ... Jakub?

Comment 3 Jakub Filak 2015-07-07 13:08:30 UTC
It should work. ABRT should be able to report crashes inside a changed root environment or a container : https://github.com/abrt/abrt/wiki/Containers-and-chroots

Comment 4 Daniel Walsh 2015-07-07 14:30:23 UTC
Since we do not know what content is in this build pool, for a security point of view, I would not want abrtd reporting on the content.

Comment 5 Vít Ondruch 2015-07-07 15:20:58 UTC
(In reply to Daniel Walsh from comment #4)
> Since we do not know what content is in this build pool, for a security
> point of view, I would not want abrtd reporting on the content.

Would you mind to explain a bit more? We know that the Ruby installed in Mock is coming from RPM, why should not ABRT report issue when the Ruby fails for some reason? I can't imagine that report from the mock chroot should be more insecure then report from my computer directly. Or is that the chroot content is not tagged "correctly" for some reasons, where my system supposedly is?

Comment 6 Jakub Filak 2015-07-08 08:28:16 UTC
(In reply to Daniel Walsh from comment #4)
> Since we do not know what content is in this build pool, for a security
> point of view, I would not want abrtd reporting on the content.

I agree that accessing data in a changed root environment is not safe (because of mount namespaces created by regular users), but I do think that experienced users like Vít should be allowed to configure ABRT to detect and report such crashes (the same apply for autonomous build and test machines).

ABRT makes copies of several files from the crashing process's root, so is there any other security issue than disclosing a private information? If there is no other issue, then I can assure you that the disclosure will not be possible too because ABRT will create a report accessible only to root.

Comment 7 kibokin 2015-08-29 00:30:12 UTC
Description of problem:
The Application is the 3D multiplayer video game "ARK: Survival Evolved" running on Valves Steam for Linux.

ARK starts up fine, but when connecting to a server and loading a map, ARK crashes to the desktop and the SELinux notification shows up.

Version-Release number of selected component:
selinux-policy-3.13.1-128.10.fc22.noarch

Additional info:
reporter:       libreport-2.6.2
hashmarkername: setroubleshoot
kernel:         4.1.5-200.fc22.x86_64
type:           libreport

Comment 8 Fedora End Of Life 2016-07-19 15:14:25 UTC
Fedora 22 changed to end-of-life (EOL) status on 2016-07-19. Fedora 22 is
no longer maintained, which means that it will not receive any further
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of
Fedora please feel free to reopen this bug against that version. If you
are unable to reopen this bug, please file a new report against the
current release. If you experience problems, please add a comment to this
bug.

Thank you for reporting this bug and we are sorry it could not be fixed.