Bug 2035117
Summary: | SELinux is preventing dhclient-script from 'write' accesses on the directory chrony-dhcp. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Mai Ling <mailinglists35> |
Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 35 | CC: | dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, pkoncity, thomas, vmojzis, zpytela |
Target Milestone: | --- | Keywords: | Triaged |
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:a031282ccb449cb77e9686ea89f6f48368f12f678454176471733f07044e2759;VARIANT_ID=workstation; | ||
Fixed In Version: | selinux-policy-35.18-1.fc35 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2022-06-23 03:13:58 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Mai Ling
2021-12-22 23:12:14 UTC
I am getting a similar, possibly related error: SELinux is preventing mkdir from create access on the directory chrony-dhcp. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that mkdir should be allowed create access on the chrony-dhcp directory by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'mkdir' --raw | audit2allow -M my-mkdir # semodule -X 300 -i my-mkdir.pp Additional Information: Source Context system_u:system_r:dhcpc_t:s0 Target Context system_u:object_r:chronyd_var_run_t:s0 Target Objects chrony-dhcp [ dir ] Source mkdir Source Path mkdir Port <Unknown> Host sarkovy Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-35.16-1.fc35.noarch Local Policy RPM selinux-policy-targeted-35.16-1.fc35.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name sarkovy Platform Linux sarkovy 5.16.18-200.fc35.x86_64 #1 SMP PREEMPT Mon Mar 28 14:10:07 UTC 2022 x86_64 x86_64 Alert Count 6 First Seen 2022-04-13 22:24:49 CEST Last Seen 2022-04-14 00:58:24 CEST Local ID 8eb1815b-a511-437a-a0a4-748d37e6bf27 Raw Audit Messages type=AVC msg=audit(1649890704.238:2102): avc: denied { create } for pid=21094 comm="mkdir" name="chrony-dhcp" scontext=system_u:system_r:dhcpc_t:s0 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=0 Hash: mkdir,dhcpc_t,chronyd_var_run_t,dir,create Fixed in rawhide, so I'll backport it to F35. FEDORA-2022-9e53cb5027 has been submitted as an update to Fedora 35. https://bodhi.fedoraproject.org/updates/FEDORA-2022-9e53cb5027 FEDORA-2022-9e53cb5027 has been pushed to the Fedora 35 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2022-9e53cb5027` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2022-9e53cb5027 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2022-9e53cb5027 has been pushed to the Fedora 35 stable repository. If problem still persists, please make note of it in this bug report. |