Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: The service systemd-modules-load failed to start Version-Release number of selected component (if applicable): systemd.x86_64 234-5.fc27 @fedora systemd-bootchart.x86_64 232-1.fc27 @updates-testing systemd-container.x86_64 234-5.fc27 @fedora systemd-debuginfo.x86_64 233-6.fc26 @updates-testing-debuginfo systemd-devel.x86_64 234-5.fc27 @fedora systemd-libs.x86_64 234-5.fc27 @fedora systemd-pam.x86_64 234-5.fc27 @fedora systemd-udev.x86_64 234-5.fc27 @fedora How reproducible: Every boot Actual results: Service failed to load Expected results: Service start Additional info: ● systemd-modules-load.service - Load Kernel Modules Loaded: loaded (/usr/lib/systemd/system/systemd-modules-load.service; static; vendor preset: disabled) Active: failed (Result: exit-code) since Tue 2017-09-19 14:39:06 -03; 2h 56min ago Docs: man:systemd-modules-load.service(8) man:modules-load.d(5) Process: 808 ExecStart=/usr/lib/systemd/systemd-modules-load (code=exited, status=1/FAILURE) Main PID: 808 (code=exited, status=1/FAILURE) Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Main process exited, code=exited, status=1/FAILURE Sep 19 14:39:01 inspiron7000 systemd[1]: Failed to start Load Kernel Modules. Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Unit entered failed state. Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Failed with result 'exit-code'. Sep 19 14:39:17 inspiron7000 systemd-modules-load[808]: libkmod: index_mm_open: mmap(NULL, 511978, PROT_READ, 4, MAP_PRIVATE, 0): Permission denied Sep 19 14:39:06 inspiron7000 systemd[1]: Starting Load Kernel Modules... Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Main process exited, code=exited, status=1/FAILURE Sep 19 14:39:06 inspiron7000 systemd[1]: Failed to start Load Kernel Modules. Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Unit entered failed state. Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Failed with result 'exit-code'.
Is this with selinux in enforcing mode? Do you have any AVCs?
Yes, selinux in enforcing mode. selinux-policy installed version: selinux-policy.noarch 3.13.1-283.3.fc27 @updates-testing selinux-policy-devel.noarch 3.13.1-283.3.fc27 @updates-testing selinux-policy-targeted.noarch 3.13.1-283.3.fc27 @updates-testing
Is there anything in the logs about permission denials from selinux? Also, if you change to "permissive", does systemd-modules-load.service succeed?
Executing the steps below the service start: 1 - setenforce 0 2 - systemctl start systemd-modules-load Log info ----- ● systemd-modules-load.service - Load Kernel Modules Loaded: loaded (/usr/lib/systemd/system/systemd-modules-load.service; static; vendor preset: disabled) Active: active (exited) since Wed 2017-09-20 15:40:43 -03; 6s ago Docs: man:systemd-modules-load.service(8) man:modules-load.d(5) Process: 9611 ExecStart=/usr/lib/systemd/systemd-modules-load (code=exited, status=0/SUCCESS) Main PID: 9611 (code=exited, status=0/SUCCESS) Sep 20 15:40:43 inspiron7000 systemd[1]: Starting Load Kernel Modules... Sep 20 15:40:43 inspiron7000 systemd[1]: Started Load Kernel Modules. Puting selinux in enforcing mode, the error message is shown again. Using the ausearch -m avc --recent i get the messages below: ---- time->Wed Sep 20 15:40:43 2017 type=AVC msg=audit(1505932843.866:423): avc: denied { map } for pid=9611 comm="systemd-modules" path="/usr/lib/modules/4.13.2-305.fc27.x86_64/modules.dep.bin" dev="dm-1" ino=2228267 scontext=system_u:system_r:systemd_modules_load_t:s0 tcontext=system_u:object_r:modules_object_t:s0 tclass=file permissive=1 ---- time->Wed Sep 20 15:42:29 2017 type=AVC msg=audit(1505932949.972:430): avc: denied { map } for pid=9680 comm="systemd-modules" path="/usr/lib/modules/4.13.2-305.fc27.x86_64/modules.dep.bin" dev="dm-1" ino=2228267 scontext=system_u:system_r:systemd_modules_load_t:s0 tcontext=system_u:object_r:modules_object_t:s0 tclass=file permissive=0
Ah, map, I have seen this before. Reassigning to selinux.
Using the versions of selinux-policy below, the service start correctly. selinux-policy-devel-3.13.1-283.10.fc27.noarch selinux-policy-targeted-3.13.1-283.10.fc27.noarch selinux-policy-3.13.1-283.10.fc27.noarch Selinux in enforcing mode.
Hi, This issue is fixed in the latest selinux-policy package. Please update.