Bug 1301252 - SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socket Unknown.
Summary: SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socke...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 24
Hardware: x86_64
OS: Unspecified
medium
high
Target Milestone: ---
Assignee: Miroslav Grepl
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:2e57041789ad59f5181e7fb6df3...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-01-23 01:52 UTC by P. A. López-Valencia
Modified: 2016-05-10 05:56 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-05-10 05:56:55 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description P. A. López-Valencia 2016-01-23 01:52:58 UTC
Description of problem:
SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socket Unknown.

*****  Plugin catchall (100. confidence) suggests   **************************

If cree que de manera predeterminada, systemd debería permitir acceso setopt sobre  Unknown unix_stream_socket.     
Then debería reportar esto como un error.
Puede generar un módulo de política local para permitir este acceso.
Do
permita el acceso momentáneamente executando:
# grep systemd /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                system_u:system_r:init_t:s0
Target Context                system_u:system_r:unconfined_service_t:s0
Target Objects                Unknown [ unix_stream_socket ]
Source                        systemd
Source Path                   systemd
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
Policy RPM                    selinux-policy-3.13.1-167.fc24.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Permissive
Host Name                     (removed)
Platform                      Linux (removed) 4.5.0-0.rc0.git1.1.fc24.x86_64 #1
                              SMP Tue Jan 12 20:40:44 UTC 2016 x86_64 x86_64
Alert Count                   1
First Seen                    2016-01-20 08:31:36 COT
Last Seen                     2016-01-20 08:31:36 COT
Local ID                      00c2bee5-c68c-4ef3-8fbb-01b29f6a4687

Raw Audit Messages
type=AVC msg=audit(1453296696.395:79): avc:  denied  { setopt } for  pid=1 comm="systemd" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=unix_stream_socket permissive=1


Hash: systemd,init_t,unconfined_service_t,unix_stream_socket,setopt

Version-Release number of selected component:
selinux-policy-3.13.1-167.fc24.noarch

Additional info:
reporter:       libreport-2.6.3
hashmarkername: setroubleshoot
kernel:         4.5.0-0.rc0.git8.1.fc24.x86_64
type:           libreport

Comment 1 Jan Kurik 2016-02-24 15:49:16 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 24 development cycle.
Changing version to '24'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora24#Rawhide_Rebase

Comment 2 Miroslav Grepl 2016-05-10 05:56:55 UTC
Should be fixed in the latest releases. Please reopen if you see it again.

Thank you.


Note You need to log in before you can comment on or make changes to this bug.