Bug 1243459 - Policy for command setting root/administrator account password
Summary: Policy for command setting root/administrator account password
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 22
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 1322407 (view as bug list)
Depends On: 1243458
Blocks: 1174176
TreeView+ depends on / blocked
 
Reported: 2015-07-15 13:25 UTC by Marc-Andre Lureau
Modified: 2016-04-03 14:13 UTC (History)
10 users (show)

Fixed In Version: selinux-policy-3.13.1-128.10.fc22
Doc Type: Bug Fix
Doc Text:
Clone Of: 1243458
Environment:
Last Closed: 2015-08-19 08:07:18 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Marc-Andre Lureau 2015-07-15 13:25:30 UTC
+++ This bug was initially created as a clone of Bug #1243458 +++

Description of problem:

qemu-ga set password command fails with SELinux enforcing:

type=AVC msg=audit(1431952168.903:567): avc:  denied  { write } for  pid=2097 comm="chpasswd" name=".pwd.lock" dev="vda1" ino=33595649 scontext=system_u:system_r:virt_qemu_ga_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file permissive=0

Comment 1 Lukas Vrabec 2015-07-28 08:06:21 UTC
HI, 
Could you describe whats going on here?

Comment 2 Marc-Andre Lureau 2015-07-28 10:21:50 UTC
(In reply to Lukas Vrabec from comment #1)
> HI, 
> Could you describe whats going on here?

Hi Lukas, check parent bug. It's qemu-ga set password command that fails because of selinux rules.

Comment 3 Lukas Vrabec 2015-07-29 10:39:08 UTC
commit f234eab38488802c3d8d1fa5bc25fee431fafd18
Author: Lukas Vrabec <lvrabec>
Date:   Wed Jul 29 11:54:26 2015 +0200

    Allow virt_qemu_ga_t domtrans to passwd_t.

commit d84c0f3bf9b11599245d2cbd908e20d99ea7f3e6
Author: Lukas Vrabec <lvrabec>
Date:   Wed Jul 29 11:52:14 2015 +0200

    Label /usr/sbin/chpasswd as passwd_exec_t.

Comment 4 Fedora Update System 2015-08-13 08:43:12 UTC
selinux-policy-3.13.1-128.10.fc22 has been submitted as an update for Fedora 22.
https://admin.fedoraproject.org/updates/selinux-policy-3.13.1-128.10.fc22

Comment 5 Fedora Update System 2015-08-15 02:20:02 UTC
Package selinux-policy-3.13.1-128.10.fc22:
* should fix your issue,
* was pushed to the Fedora 22 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.13.1-128.10.fc22'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2015-13501/selinux-policy-3.13.1-128.10.fc22
then log in and leave karma (feedback).

Comment 6 Fedora Update System 2015-08-19 08:07:18 UTC
selinux-policy-3.13.1-128.10.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 7 Diana Clarke 2016-04-03 14:13:10 UTC
*** Bug 1322407 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.