Bug 1943697
| Summary: | SELinux is preventing f2b/f.selinux-s from 'watch' accesses on the dossier /run/log/journal. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Nicolas Berrehouc <nberrehouc> |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 34 | CC: | dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, plautrba, vmojzis, zpytela |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Unspecified | ||
| Whiteboard: | abrt_hash:950dd16deac4cf2aecaa48057c6cb38a818fa9e53eadcfed7de45783e3fa8ef9;VARIANT_ID=workstation; | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-01-26 17:09:51 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
*** Bug 1943786 has been marked as a duplicate of this bug. *** *** This bug has been marked as a duplicate of bug 1943696 *** |
Description of problem: After upgrading from F33 to F34 Beta. SELinux is preventing f2b/f.selinux-s from 'watch' accesses on the dossier /run/log/journal. ***** Plugin catchall (100. confidence) suggests ************************** Si vous pensez que f.selinux-s devrait être autorisé à accéder watch sur journal directory par défaut. Then vous devriez rapporter ceci en tant qu'anomalie. Vous pouvez générer un module de stratégie local pour autoriser cet accès. Do autoriser cet accès pour le moment en exécutant : # ausearch -c "f2b/f.selinux-s" --raw | audit2allow -M my-f2bfselinuxs # semodule -X 300 -i my-f2bfselinuxs.pp Additional Information: Source Context system_u:system_r:fail2ban_t:s0 Target Context system_u:object_r:syslogd_var_run_t:s0 Target Objects /run/log/journal [ dir ] Source f2b/f.selinux-s Source Path f2b/f.selinux-s Port <Inconnu> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-3.14.7-27.fc34.noarch Local Policy RPM selinux-policy-targeted-3.14.7-27.fc34.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 5.11.9-300.fc34.x86_64 #1 SMP Wed Mar 24 12:06:51 UTC 2021 x86_64 x86_64 Alert Count 1 First Seen 2021-03-26 21:05:38 CET Last Seen 2021-03-26 21:05:38 CET Local ID cd09a138-0b2e-4367-b7fb-b34d610ef81f Raw Audit Messages type=AVC msg=audit(1616789138.917:526): avc: denied { watch } for pid=814 comm="f2b/f.selinux-s" path="/run/log/journal" dev="tmpfs" ino=55 scontext=system_u:system_r:fail2ban_t:s0 tcontext=system_u:object_r:syslogd_var_run_t:s0 tclass=dir permissive=0 Hash: f2b/f.selinux-s,fail2ban_t,syslogd_var_run_t,dir,watch Version-Release number of selected component: selinux-policy-targeted-3.14.7-27.fc34.noarch Additional info: component: selinux-policy reporter: libreport-2.14.0 hashmarkername: setroubleshoot kernel: 5.11.9-300.fc34.x86_64 type: libreport