Bug 2347136
| Summary: | SELinux is preventing /usr/lib/systemd/systemd-homed from 'getattr' accesses on the filesystem /dev/shm. | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Joel Craycroft <chaosjs0010> | ||||||
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> | ||||||
| Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> | ||||||
| Severity: | unspecified | Docs Contact: | |||||||
| Priority: | unspecified | ||||||||
| Version: | 41 | CC: | chaosjs0010, dwalsh, lvrabec, mmalik, omosnacek, pkoncity, vmojzis, zpytela | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | x86_64 | ||||||||
| OS: | Unspecified | ||||||||
| Whiteboard: | abrt_hash:dd53fe27a63edddf72f5bb046556f60bce35744d24f07c0f329e0361d1159e27;VARIANT_ID=cinnamon; | ||||||||
| Fixed In Version: | selinux-policy-41.47-1.fc41 | Doc Type: | --- | ||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2025-09-14 01:35:22 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
Created attachment 2077416 [details]
File: description
Created attachment 2077417 [details]
File: os_info
Hi, can you temporarily switch to SELinux permissive mode and collect all denials? Full auditing would be nice enhancement. Do you happen to know what is the condition needed to trigger this denial? https://fedoraproject.org/wiki/SELinux/Debugging#Enable_full_auditing setenforce 0 <reproduce> setenforce 1 Hello, I am not quite sure because at the time the issue occurred I had booted from a usb flash drive live usb on Fedora Linux Cinnamon Version 41 at the time. So, Sorry about that anyways!. Have a great day ahead anyways and stay safe also.. FEDORA-2025-acfddac85e (selinux-policy-41.47-1.fc41) has been submitted as an update to Fedora 41. https://bodhi.fedoraproject.org/updates/FEDORA-2025-acfddac85e FEDORA-2025-acfddac85e has been pushed to the Fedora 41 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-acfddac85e` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-acfddac85e See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates. FEDORA-2025-acfddac85e (selinux-policy-41.47-1.fc41) has been pushed to the Fedora 41 stable repository. If problem still persists, please make note of it in this bug report. |
Description of problem: SELinux is preventing /usr/lib/systemd/systemd-homed from 'getattr' accesses on the filesystem /dev/shm. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that systemd-homed should be allowed getattr access on the shm filesystem by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'systemd-homed' --raw | audit2allow -M my-systemdhomed # semodule -X 300 -i my-systemdhomed.pp Additional Information: Source Context system_u:system_r:systemd_homed_t:s0 Target Context system_u:object_r:tmpfs_t:s0 Target Objects /dev/shm [ filesystem ] Source systemd-homed Source Path /usr/lib/systemd/systemd-homed Port <Unknown> Host (removed) Source RPM Packages systemd-udev-256.7-1.fc41.x86_64 Target RPM Packages SELinux Policy RPM selinux-policy-targeted-41.20-1.fc41.noarch Local Policy RPM selinux-policy-targeted-41.20-1.fc41.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.11.4-301.fc41.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Oct 20 15:02:33 UTC 2024 x86_64 Alert Count 1 First Seen 2025-02-22 20:51:35 EST Last Seen 2025-02-22 20:51:35 EST Local ID d011d1a5-a8a0-44c6-85b3-f538f319c57d Raw Audit Messages type=AVC msg=audit(1740275495.25:88): avc: denied { getattr } for pid=1711 comm="systemd-homed" name="/" dev="tmpfs" ino=1 scontext=system_u:system_r:systemd_homed_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=filesystem permissive=0 type=SYSCALL msg=audit(1740275495.25:88): arch=x86_64 syscall=statfs success=no exit=EACCES a0=7f5769b39b60 a1=7ffcebf5a6f0 a2=11 a3=55efd1227db0 items=0 ppid=1 pid=1711 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=systemd-homed exe=/usr/lib/systemd/systemd-homed subj=system_u:system_r:systemd_homed_t:s0 key=(null) Hash: systemd-homed,systemd_homed_t,tmpfs_t,filesystem,getattr Version-Release number of selected component: selinux-policy-targeted-41.20-1.fc41.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing /usr/lib/systemd/systemd-homed from 'getattr' accesses on the filesystem /dev/shm. package: selinux-policy-targeted-41.20-1.fc41.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.11.4-301.fc41.x86_64 component: selinux-policy