Bug 2184731
| Summary: | SELinux is preventing pool-geoclue from 'search' accesses on the adresář net. | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Vít Ondruch <vondruch> | ||||||
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | ||||||
| Status: | NEW --- | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | unspecified | ||||||||
| Version: | 39 | CC: | dwalsh, lvrabec, mmalik, omosnacek, pkoncity, vmojzis, vondruch, zpytela | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | x86_64 | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | abrt_hash:fed0813b2e6b27c47a9df2ffeb1e5266ff654147648cf887397f1789d8dd147d;VARIANT_ID=workstation; | ||||||||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | Type: | --- | |||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
Created attachment 1955899 [details]
File: description
Created attachment 1955900 [details]
File: os_info
This bug appears to have been reported against 'rawhide' during the Fedora Linux 39 development cycle. Changing version to 39. |
Description of problem: SELinux is preventing pool-geoclue from 'search' accesses on the adresář net. ***** Plugin catchall (100. confidence) suggests ************************** Pokud jste přesvědčeni, že má pool-geoclue mít ve výchozím stavu přístup search na net directory. Then měli byste tento problém nahlásit jako chybu. Abyste přístup povolili, můžete vygenerovat lokální modul pravidel. Do prozatím tento přístup povolíte příkazy: # ausearch -c 'pool-geoclue' --raw | audit2allow -M my-poolgeoclue # semodule -X 300 -i my-poolgeoclue.pp Additional Information: Source Context system_u:system_r:geoclue_t:s0 Target Context system_u:object_r:sysctl_net_t:s0 Target Objects net [ dir ] Source pool-geoclue Source Path pool-geoclue Port <Neznámé> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-38.9-1.fc39.noarch Local Policy RPM selinux-policy-targeted-38.9-1.fc39.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.2.9-300.fc38.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Mar 30 22:32:58 UTC 2023 x86_64 Alert Count 25 First Seen 2023-04-05 16:00:22 CEST Last Seen 2023-04-05 16:16:03 CEST Local ID 11d03951-b23f-4b78-9612-83ad9443f684 Raw Audit Messages type=AVC msg=audit(1680704163.83:225): avc: denied { search } for pid=1217 comm="pool-geoclue" name="net" dev="proc" ino=28993 scontext=system_u:system_r:geoclue_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=dir permissive=0 Hash: pool-geoclue,geoclue_t,sysctl_net_t,dir,search Version-Release number of selected component: selinux-policy-targeted-38.9-1.fc39.noarch Additional info: reporter: libreport-2.17.9 reason: SELinux is preventing pool-geoclue from 'search' accesses on the adresář net. package: selinux-policy-targeted-38.9-1.fc39.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.2.9-300.fc38.x86_64 component: selinux-policy