Bug 1969740

Summary: avc: denied { getattr } for pid=5052 comm="unix_chkpwd" name="/" dev="proc"
Product: Red Hat Enterprise Linux 8 Reporter: Frank Liang <xiliang>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED DUPLICATE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: medium Docs Contact:
Priority: medium    
Version: 8.5CC: leiwang, linl, lvrabec, mmalik, plautrba, ribarry, ssekidde, vkuznets, ymao
Target Milestone: betaKeywords: Regression
Target Release: 8.5   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-06-09 10:12:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Frank Liang 2021-06-09 07:33:08 UTC
Description of problem:
Started a RHEL-8.5.0-20210609.n.0 guest and found below avc denied log.

# ausearch -m avc
----
time->Wed Jun  9 07:22:15 2021
type=PROCTITLE msg=audit(1623223335.023:155): proctitle=2F7573722F7362696E2F756E69785F63686B707764006563322D757365720063686B657870697279
type=SYSCALL msg=audit(1623223335.023:155): arch=c000003e syscall=138 success=no exit=-13 a0=3 a1=7ffce016f630 a2=0 a3=0 items=0 ppid=5051 pid=5052 auid=1000 uid=0 gid=1000 euid=0 suid=0 fsuid=0 egid=1000 sgid=1000 fsgid=1000 tty=(none) ses=1 comm="unix_chkpwd" exe="/usr/sbin/unix_chkpwd" subj=unconfined_u:unconfined_r:chkpwd_t:s0-s0:c0.c1023 key=(null)
type=AVC msg=audit(1623223335.023:155): avc:  denied  { getattr } for  pid=5052 comm="unix_chkpwd" name="/" dev="proc" ino=1 scontext=unconfined_u:unconfined_r:chkpwd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:proc_t:s0 tclass=filesystem permissive=0

Version-Release number of selected components (if applicable):

RHEL Version:
RHEL-8.5(4.18.0-310.el8.x86_64)

How reproducible:
100%

Steps to Reproduce:
1. start a RHEL-8.5
2. check avc log

Actual results:
unix_chkpwd is denied.

Expected results:
no such log

Additional info:
No such error in RHEL-8.5.0-20210604.n.0.

Comment 1 Zdenek Pytela 2021-06-09 10:12:28 UTC

*** This bug has been marked as a duplicate of bug 1967125 ***