Bug 2053857
| Summary: | SELinux is preventing locate from 'map' accesses on the anon_inode anon_inode. | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Davide Repetto <red> |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | CLOSED DUPLICATE | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
| Severity: | unspecified | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 35 | CC: | dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, pkoncity, vmojzis, zpytela |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Unspecified | ||
| Whiteboard: | abrt_hash:d704d44ff0af890030a05de55a3ff1feb00d7cad5895a4d0a2c7c44123b470bb;VARIANT_ID=matecompiz; | ||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2022-02-14 09:48:58 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
*** This bug has been marked as a duplicate of bug 2025714 *** |
Description of problem: SELinux is preventing locate from 'map' accesses on the anon_inode anon_inode. ***** Plugin catchall (100. confidence) suggests ************************** Se ci credi locate dovrebbe essere consentito map accesso al anon_inode anon_inode per impostazione predefinita. Then si dovrebbe riportare il problema come bug. E' possibile generare un modulo di politica locale per consentire questo accesso. Do consentire questo accesso per ora eseguendo: # ausearch -c 'locate' --raw | audit2allow -M my-$MODULE_NOME # semodule -X 300 -i miei-locate.pp Additional Information: Source Context unconfined_u:unconfined_r:unconfined_t:s0- s0:c0.c1023 Target Context unconfined_u:object_r:unconfined_t:s0 Target Objects anon_inode [ anon_inode ] Source locate Source Path locate Port <Sconosciuto> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-35.13-1.fc35.noarch Local Policy RPM selinux-policy-targeted-35.13-1.fc35.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 5.16.8-200.fc35.x86_64 #1 SMP PREEMPT Tue Feb 8 20:58:59 UTC 2022 x86_64 x86_64 Alert Count 1 First Seen 2022-02-12 18:50:09 CET Last Seen 2022-02-12 18:50:09 CET Local ID 5347a2d1-56f6-4890-879c-e97dab0a1d4b Raw Audit Messages type=AVC msg=audit(1644688209.876:547): avc: denied { map } for pid=135687 comm="locate" path="anon_inode:[io_uring]" dev="anon_inodefs" ino=16530965 scontext=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:unconfined_t:s0 tclass=anon_inode permissive=1 Hash: locate,unconfined_t,unconfined_t,anon_inode,map Version-Release number of selected component: selinux-policy-targeted-35.13-1.fc35.noarch Additional info: component: selinux-policy reporter: libreport-2.15.2 hashmarkername: setroubleshoot kernel: 5.16.8-200.fc35.x86_64 type: libreport