Bug 1847221
Summary: | [RHEL8]: avc: denied { write } for pid=21161 comm="smbd" name="krb5_0.rcache2" | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 8 | Reporter: | xiaoli feng <xifeng> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED DUPLICATE | QA Contact: | Milos Malik <mmalik> |
Severity: | high | Docs Contact: | |
Priority: | medium | ||
Version: | 8.3 | CC: | lmiksik, lvrabec, mmalik, plautrba, ssekidde, xzhou, yoyang, zpytela |
Target Milestone: | rc | Keywords: | Triaged |
Target Release: | 8.3 | ||
Hardware: | Unspecified | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | If docs needed, set a value | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2020-07-27 16:17:51 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1842946 |
Description
xiaoli feng
2020-06-16 00:48:18 UTC
I believe this bug is a duplicate of BZ#1841488. Please set the system into SELinux permissive mode to gather all possible subsequent denials: # setenforce 0 <reproduce> # ausearch -i -m avc,user_avc -ts recent You created this bugzilla with the severity of Urgent. This means: catastrophic issues which severely impact the mission-critical operations of an organization. This may mean that the operational servers, development systems or customer applications are down or not functioning and no procedural workaround exists. Please explain the impact so that we can act accordingly. As an immediate workaround, turn on the samba_export_all_rw boolean: # setsebool -P samba_export_all_rw on (In reply to Zdenek Pytela from comment #2) > Please set the system into SELinux permissive mode to gather all possible > subsequent denials: > > # setenforce 0 > <reproduce> > # ausearch -i -m avc,user_avc -ts recent # ausearch -i -m avc,user_avc -ts recent ---- type=USER_AVC msg=audit(06/22/2020 03:29:47.729:391) : pid=723 uid=dbus auid=unset ses=unset subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc: received setenforce notice (enforcing=1) exe=/usr/bin/dbus-daemon sauid=dbus hostname=? addr=? terminal=?' ---- type=USER_AVC msg=audit(06/22/2020 03:30:01.467:393) : pid=723 uid=dbus auid=unset ses=unset subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc: received setenforce notice (enforcing=0) exe=/usr/bin/dbus-daemon sauid=dbus hostname=? addr=? terminal=?' ---- type=PROCTITLE msg=audit(06/22/2020 03:31:07.236:394) : proctitle=/usr/sbin/smbd --foreground --no-process-group type=SYSCALL msg=audit(06/22/2020 03:31:07.236:394) : arch=x86_64 syscall=openat success=yes exit=14 a0=0xffffff9c a1=0x55660a9d1100 a2=O_RDWR|O_CREAT|O_NOFOLLOW a3=0x180 items=0 ppid=22724 pid=25960 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=smbd exe=/usr/sbin/smbd subj=system_u:system_r:smbd_t:s0 key=(null) type=AVC msg=audit(06/22/2020 03:31:07.236:394) : avc: denied { write } for pid=25960 comm=smbd name=krb5_0.rcache2 dev="dm-0" ino=101548621 scontext=system_u:system_r:smbd_t:s0 tcontext=system_u:object_r:kadmind_tmp_t:s0 tclass=file permissive=1 > > You created this bugzilla with the severity of Urgent. This means: > > catastrophic issues which severely impact the mission-critical > operations of an organization. This may mean that the operational servers, > development systems or customer applications are down or not functioning and > no procedural workaround exists. > > Please explain the impact so that we can act accordingly. In RHEL-8.2, this issue doesn't exist. The cifs can be mounted with krb5 with selinux on. But in RHEL-8.3, it need to turn off selinux. That's why I set this bug urgent. But now I know setting samba_export_all_rw on also can fix this issue. > > As an immediate workaround, turn on the samba_export_all_rw boolean: > > # setsebool -P samba_export_all_rw on After set samba_export_all_rw on, this issue also doesn't exist. Given the workaround helps to make the scenario working, I am adjusting the severity/priority. Note this can not be considered as a solution. Please refer to bz#1848953, we may find a way how to resolve the issue generally and eventually make this bz a duplicate. This bug was created earlier than bz#1848953. So I think bz#1848953 is a duplicate of this bz. Hello Zdenek, what's going on for this bug? Thanks. Hello Zdenet, Could you provide devel_ack+? Thanks. Hello Milos, Could you provide qa_ack+? Thanks. This bug will be eventually resolved together with other similar bugs. Closing as a dup of bz#1848953 which contains the most of information. *** This bug has been marked as a duplicate of bug 1848953 *** The needinfo request[s] on this closed bug have been removed as they have been unresolved for 1000 days |