Bug 1971688

Summary: Since rebase to 0.7.11, SELinux failures from multiple things
Product: Red Hat Enterprise Linux 8 Reporter: Chris Adams <linux>
Component: libcap-ngAssignee: Zoltan Fridrich <zfridric>
Status: CLOSED DUPLICATE QA Contact: BaseOS QE Security Team <qe-baseos-security>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: CentOS StreamCC: bstinson, jwboyer, rsroka, zpytela
Target Milestone: betaFlags: pm-rhel: mirror+
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-06-14 16:47:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Chris Adams 2021-06-14 15:00:31 UTC
Since the rebase to 0.7.11, multiple things are logging SELinux failures on an fstatfs on /proc. I see the failures on sssd_be startup and unix_chkpwd for every login. The failures look like:

type=AVC msg=audit(1623682802.771:128): avc:  denied  { getattr } for  pid=1326 comm="unix_chkpwd" name="/" dev="proc" ino=1 scontext=system_u:system_r:chkpwd_t:s0 tcontext=system_u:object_r:proc_t:s0 tclass=filesystem permissive=0

Comment 1 Zdenek Pytela 2021-06-14 16:47:55 UTC

*** This bug has been marked as a duplicate of bug 1967125 ***