Bug 1301252 - SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socket Unknown.
SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socke...
Product: Fedora
Classification: Fedora
Component: selinux-policy (Show other bugs)
x86_64 Unspecified
medium Severity high
: ---
: ---
Assigned To: Miroslav Grepl
Fedora Extras Quality Assurance
Depends On:
  Show dependency treegraph
Reported: 2016-01-22 20:52 EST by P. A. López-Valencia
Modified: 2016-05-10 01:56 EDT (History)
5 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2016-05-10 01:56:55 EDT
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description P. A. López-Valencia 2016-01-22 20:52:58 EST
Description of problem:
SELinux is preventing systemd from 'setopt' accesses on the unix_stream_socket Unknown.

*****  Plugin catchall (100. confidence) suggests   **************************

If cree que de manera predeterminada, systemd debería permitir acceso setopt sobre  Unknown unix_stream_socket.     
Then debería reportar esto como un error.
Puede generar un módulo de política local para permitir este acceso.
permita el acceso momentáneamente executando:
# grep systemd /var/log/audit/audit.log | audit2allow -M mypol
# semodule -i mypol.pp

Additional Information:
Source Context                system_u:system_r:init_t:s0
Target Context                system_u:system_r:unconfined_service_t:s0
Target Objects                Unknown [ unix_stream_socket ]
Source                        systemd
Source Path                   systemd
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
Policy RPM                    selinux-policy-3.13.1-167.fc24.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Permissive
Host Name                     (removed)
Platform                      Linux (removed) 4.5.0-0.rc0.git1.1.fc24.x86_64 #1
                              SMP Tue Jan 12 20:40:44 UTC 2016 x86_64 x86_64
Alert Count                   1
First Seen                    2016-01-20 08:31:36 COT
Last Seen                     2016-01-20 08:31:36 COT
Local ID                      00c2bee5-c68c-4ef3-8fbb-01b29f6a4687

Raw Audit Messages
type=AVC msg=audit(1453296696.395:79): avc:  denied  { setopt } for  pid=1 comm="systemd" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:unconfined_service_t:s0 tclass=unix_stream_socket permissive=1

Hash: systemd,init_t,unconfined_service_t,unix_stream_socket,setopt

Version-Release number of selected component:

Additional info:
reporter:       libreport-2.6.3
hashmarkername: setroubleshoot
kernel:         4.5.0-0.rc0.git8.1.fc24.x86_64
type:           libreport
Comment 1 Jan Kurik 2016-02-24 10:49:16 EST
This bug appears to have been reported against 'rawhide' during the Fedora 24 development cycle.
Changing version to '24'.

More information and reason for this action is here:
Comment 2 Miroslav Grepl 2016-05-10 01:56:55 EDT
Should be fixed in the latest releases. Please reopen if you see it again.

Thank you.

Note You need to log in before you can comment on or make changes to this bug.