Bug 1500737

Summary: SELinux is preventing gsf-office-thum from 'map' accesses on the fichier 2F72756E2F6D656469612F746573742F363346363534303632374143324430362F4C69737465206465732070726F6772616D6D65206E6F6E20646973706F20706F7572206665646F72612032372E6F6473.
Product: [Fedora] Fedora Reporter: Morgan <toudicmorgan>
Component: selinux-policyAssignee: Lukas Vrabec <lvrabec>
Status: CLOSED ERRATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 27CC: aekrizi, arturpolak1, dwalsh, jan.public, lsm5, lvrabec, mgrepl, oleg-sz, plautrba, pmoore, ricky.tigg, sr7nekoggop
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
Whiteboard: abrt_hash:f81acee03d212ca55a75b7407024329e270b69a5960c458cb131c7978c5f303d;
Fixed In Version: selinux-policy-3.13.1-283.19.fc27 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2018-01-02 16:48:54 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Morgan 2017-10-11 11:56:52 UTC
Description of problem:
SELinux is preventing gsf-office-thum from 'map' accesses on the fichier 2F72756E2F6D656469612F746573742F363346363534303632374143324430362F4C69737465206465732070726F6772616D6D65206E6F6E20646973706F20706F7572206665646F72612032372E6F6473.

*****  Plugin catchall (100. confidence) suggests   **************************

If vous pensez que gsf-office-thum devrait être autorisé à accéder map sur 2F72756E2F6D656469612F746573742F363346363534303632374143324430362F4C69737465206465732070726F6772616D6D65206E6F6E20646973706F20706F7572206665646F72612032372E6F6473 file par défaut.
Then vous devriez rapporter ceci en tant qu'anomalie.
Vous pouvez générer un module de stratégie local pour autoriser cet accès.
Do
allow this access for now by executing:
# ausearch -c 'gsf-office-thum' --raw | audit2allow -M my-gsfofficethum
# semodule -X 300 -i my-gsfofficethum.pp

Additional Information:
Source Context                unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023
Target Context                system_u:object_r:fusefs_t:s0
Target Objects                2F72756E2F6D656469612F746573742F363346363534303632
                              374143324430362F4C69737465206465732070726F6772616D
                              6D65206E6F6E20646973706F20706F7572206665646F726120
                              32372E6F6473 [ file ]
Source                        gsf-office-thum
Source Path                   gsf-office-thum
Port                          <Inconnu>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
Policy RPM                    selinux-policy-3.13.1-283.5.fc27.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 4.13.5-300.fc27.x86_64 #1 SMP Thu
                              Oct 5 16:57:11 UTC 2017 x86_64 x86_64
Alert Count                   2
First Seen                    2017-10-10 21:32:33 CEST
Last Seen                     2017-10-11 13:50:11 CEST
Local ID                      a556d68b-16ae-424a-a453-d0286eb4dbfc

Raw Audit Messages
type=AVC msg=audit(1507722611.425:231): avc:  denied  { map } for  pid=1997 comm="gsf-office-thum" path=2F72756E2F6D656469612F746573742F363346363534303632374143324430362F4C69737465206465732070726F6772616D6D65206E6F6E20646973706F20706F7572206665646F72612032372E6F6473 dev="sdb1" ino=64 scontext=unconfined_u:unconfined_r:thumb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:fusefs_t:s0 tclass=file permissive=0


Hash: gsf-office-thum,thumb_t,fusefs_t,file,map

Version-Release number of selected component:
selinux-policy-3.13.1-283.5.fc27.noarch

Additional info:
component:      selinux-policy
reporter:       libreport-2.9.2
hashmarkername: setroubleshoot
kernel:         4.13.5-300.fc27.x86_64
type:           libreport

Potential duplicate: bug 1487282

Comment 1 ricky.tigg 2017-11-23 13:01:24 UTC
Description of problem:
Virtual Machine Manager 1.4.3 needs to access an ISO image file located on an external USB device formatted with NTFS.

Version-Release number of selected component:
selinux-policy-3.13.1-283.16.fc27.noarch

Additional info:
reporter:       libreport-2.9.3
hashmarkername: setroubleshoot
kernel:         4.13.13-300.fc27.x86_64
type:           libreport

Comment 2 ricky.tigg 2017-11-29 09:46:08 UTC
Description of problem:
Same description.

Version-Release number of selected component:
selinux-policy-3.13.1-283.16.fc27.noarch

Additional info:
reporter:       libreport-2.9.3
hashmarkername: setroubleshoot
kernel:         4.13.15-300.fc27.x86_64
type:           libreport

Comment 3 ricky.tigg 2017-11-30 09:54:04 UTC
Description of problem:
On Xfce environment. It occurs when I select the USB device for launching the file manager.

Version-Release number of selected component:
selinux-policy-3.13.1-283.16.fc27.noarch

Additional info:
reporter:       libreport-2.9.3
hashmarkername: setroubleshoot
kernel:         4.13.15-300.fc27.x86_64
type:           libreport

Comment 4 Fedora Update System 2017-12-13 08:28:19 UTC
selinux-policy-3.13.1-283.18.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-8225c4e502

Comment 5 Fedora Update System 2017-12-14 11:13:02 UTC
selinux-policy-3.13.1-283.18.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-8225c4e502

Comment 6 ricky.tigg 2017-12-15 11:40:19 UTC
Following the instructions mentioned in document from the link provided in comment #9, in host machine, the output from the command 
$ sudo dnf install -y selinux-policy –enablerepo=updates-testing
is:
Package selinux-policy-3.13.1-283.17.fc27.noarch is already installed, skipping.

As a result the component installed remains the one from the Fedora 27 updates repository (selinux-policy-3.13.1-283.17.fc27.noarch).

Comment 7 Fedora Update System 2017-12-20 11:26:08 UTC
selinux-policy-3.13.1-283.19.fc27 has been submitted as an update to Fedora 27. https://bodhi.fedoraproject.org/updates/FEDORA-2017-8225c4e502

Comment 8 aekryz 2017-12-20 22:20:31 UTC
*** Bug 1528061 has been marked as a duplicate of this bug. ***

Comment 9 Fedora Update System 2017-12-21 20:22:05 UTC
selinux-policy-3.13.1-283.19.fc27 has been pushed to the Fedora 27 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2017-8225c4e502

Comment 10 ricky.tigg 2017-12-22 10:39:38 UTC
Situation illustrated in Comment 6 is still alive.

Comment 11 Jan Vlug 2017-12-25 20:24:32 UTC
Description of problem:
Copying files from disk to usb stick.

Version-Release number of selected component:
selinux-policy-3.13.1-283.17.fc27.noarch

Additional info:
reporter:       libreport-2.9.3
hashmarkername: setroubleshoot
kernel:         4.14.7-300.fc27.x86_64
type:           libreport

Comment 12 Fedora Update System 2018-01-02 16:48:54 UTC
selinux-policy-3.13.1-283.19.fc27 has been pushed to the Fedora 27 stable repository. If problems still persist, please make note of it in this bug report.