Bug 1425408

Summary: avc denied chown for chronyd
Product: Red Hat Enterprise Linux 7 Reporter: Radka Brychtova <rskvaril>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED DUPLICATE QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: medium    
Version: 7.4CC: lvrabec, mgrepl, mmalik, plautrba, pvrabec, ssekidde
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-02-21 13:04:31 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Radka Brychtova 2017-02-21 11:40:12 UTC
Description of problem:
AVC message:
time->Mon Feb 20 16:13:03 2017
type=SYSCALL msg=audit(1487625183.534:134): arch=c000003e syscall=92 success=no exit=-1 a0=7f2f4f8e1020 a1=3e1 a2=3de a3=7f2f4dc9a6c0 items=0 ppid=1 pid=13455 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="chronyd" exe="/usr/sbin/chronyd" subj=system_u:system_r:chronyd_t:s0 key=(null)
type=AVC msg=audit(1487625183.534:134): avc:  denied  { chown } for  pid=13455 comm="chronyd" capability=0  scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:system_r:chronyd_t:s0 tclass=capability



Version-Release number of selected component (if applicable):
selinux-policy-3.13.1-117.el7.noarch
systemd-219-31.el7.x86_64
chrony-3.1-1.el7.x86_64

How reproducible:
allways

Steps to Reproduce:
1. start chronyd service
2.
3.

Actual results:
AVC error

Expected results:
Clean AVC

Additional info:
different result from 1minute-tip:
type=SYSCALL msg=audit(02/21/2017 06:36:05.602:348) : arch=x86_64 syscall=chown success=no exit=EPERM(Operation not permitted) a0=0x7f243d2baf30 a1=chrony a2=chrony a3=0x7f243b78b6c0 items=0 ppid=1 pid=1534 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=chronyd exe=/usr/sbin/chronyd subj=system_u:system_r:chronyd_t:s0 key=(null) 
type=AVC msg=audit(02/21/2017 06:36:05.602:348) : avc:  denied  { chown } for  pid=1534 comm=chronyd capability=chown  scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:system_r:chronyd_t:s0 tclass=capability

Comment 2 Radka Brychtova 2017-02-21 13:04:31 UTC

*** This bug has been marked as a duplicate of bug 1421248 ***