Bug 1493293 - Service systemd-modules-load failed to start
Summary: Service systemd-modules-load failed to start
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy-targeted
Version: 27
Hardware: x86_64
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Ben Levenson
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-09-19 20:37 UTC by Gleidson Baleeiro
Modified: 2020-05-13 15:50 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2017-11-07 09:04:18 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Gleidson Baleeiro 2017-09-19 20:37:39 UTC
Description of problem:

The service systemd-modules-load failed to start


Version-Release number of selected component (if applicable):

systemd.x86_64                         234-5.fc27              @fedora          
systemd-bootchart.x86_64               232-1.fc27              @updates-testing 
systemd-container.x86_64               234-5.fc27              @fedora          
systemd-debuginfo.x86_64               233-6.fc26              @updates-testing-debuginfo
systemd-devel.x86_64                   234-5.fc27              @fedora          
systemd-libs.x86_64                    234-5.fc27              @fedora          
systemd-pam.x86_64                     234-5.fc27              @fedora          
systemd-udev.x86_64                    234-5.fc27              @fedora          


How reproducible:

Every boot


Actual results:
Service failed to load

Expected results:
Service start 

Additional info:

● systemd-modules-load.service - Load Kernel Modules
   Loaded: loaded (/usr/lib/systemd/system/systemd-modules-load.service; static; vendor preset: disabled)
   Active: failed (Result: exit-code) since Tue 2017-09-19 14:39:06 -03; 2h 56min ago
     Docs: man:systemd-modules-load.service(8)
           man:modules-load.d(5)
  Process: 808 ExecStart=/usr/lib/systemd/systemd-modules-load (code=exited, status=1/FAILURE)
 Main PID: 808 (code=exited, status=1/FAILURE)

Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Main process exited, code=exited, status=1/FAILURE
Sep 19 14:39:01 inspiron7000 systemd[1]: Failed to start Load Kernel Modules.
Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Unit entered failed state.
Sep 19 14:39:01 inspiron7000 systemd[1]: systemd-modules-load.service: Failed with result 'exit-code'.
Sep 19 14:39:17 inspiron7000 systemd-modules-load[808]: libkmod: index_mm_open: mmap(NULL, 511978, PROT_READ, 4, MAP_PRIVATE, 0): Permission denied
Sep 19 14:39:06 inspiron7000 systemd[1]: Starting Load Kernel Modules...
Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Main process exited, code=exited, status=1/FAILURE
Sep 19 14:39:06 inspiron7000 systemd[1]: Failed to start Load Kernel Modules.
Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Unit entered failed state.
Sep 19 14:39:06 inspiron7000 systemd[1]: systemd-modules-load.service: Failed with result 'exit-code'.

Comment 1 Zbigniew Jędrzejewski-Szmek 2017-09-19 20:55:08 UTC
Is this with selinux in enforcing mode? Do you have any AVCs?

Comment 2 Gleidson Baleeiro 2017-09-19 21:13:22 UTC
Yes, selinux in enforcing mode. 

selinux-policy installed version:

selinux-policy.noarch                  3.13.1-283.3.fc27       @updates-testing 
selinux-policy-devel.noarch            3.13.1-283.3.fc27       @updates-testing 
selinux-policy-targeted.noarch         3.13.1-283.3.fc27       @updates-testing

Comment 3 Zbigniew Jędrzejewski-Szmek 2017-09-20 05:10:21 UTC
Is there anything in the logs about permission denials from selinux?
Also, if you change to "permissive", does systemd-modules-load.service succeed?

Comment 4 Gleidson Baleeiro 2017-09-20 18:47:40 UTC
Executing the steps below the service start:

1 - setenforce 0 
2 - systemctl start systemd-modules-load 

Log info -----
● systemd-modules-load.service - Load Kernel Modules
   Loaded: loaded (/usr/lib/systemd/system/systemd-modules-load.service; static; vendor preset: disabled)
   Active: active (exited) since Wed 2017-09-20 15:40:43 -03; 6s ago
     Docs: man:systemd-modules-load.service(8)
           man:modules-load.d(5)
  Process: 9611 ExecStart=/usr/lib/systemd/systemd-modules-load (code=exited, status=0/SUCCESS)
 Main PID: 9611 (code=exited, status=0/SUCCESS)

Sep 20 15:40:43 inspiron7000 systemd[1]: Starting Load Kernel Modules...
Sep 20 15:40:43 inspiron7000 systemd[1]: Started Load Kernel Modules.


Puting selinux in enforcing mode, the error message is shown again.

Using the ausearch -m avc --recent i get the messages below:

----
time->Wed Sep 20 15:40:43 2017
type=AVC msg=audit(1505932843.866:423): avc:  denied  { map } for  pid=9611 comm="systemd-modules" path="/usr/lib/modules/4.13.2-305.fc27.x86_64/modules.dep.bin" dev="dm-1" ino=2228267 scontext=system_u:system_r:systemd_modules_load_t:s0 tcontext=system_u:object_r:modules_object_t:s0 tclass=file permissive=1
----
time->Wed Sep 20 15:42:29 2017
type=AVC msg=audit(1505932949.972:430): avc:  denied  { map } for  pid=9680 comm="systemd-modules" path="/usr/lib/modules/4.13.2-305.fc27.x86_64/modules.dep.bin" dev="dm-1" ino=2228267 scontext=system_u:system_r:systemd_modules_load_t:s0 tcontext=system_u:object_r:modules_object_t:s0 tclass=file permissive=0

Comment 5 Zbigniew Jędrzejewski-Szmek 2017-09-20 18:57:33 UTC
Ah, map, I have seen this before. Reassigning to selinux.

Comment 6 Gleidson Baleeiro 2017-11-01 17:58:05 UTC
Using the versions of selinux-policy below, the service start correctly.

selinux-policy-devel-3.13.1-283.10.fc27.noarch
selinux-policy-targeted-3.13.1-283.10.fc27.noarch
selinux-policy-3.13.1-283.10.fc27.noarch 

Selinux in enforcing mode.

Comment 7 Lukas Vrabec 2017-11-07 09:04:18 UTC
Hi, 

This issue is fixed in the latest selinux-policy package. Please update.


Note You need to log in before you can comment on or make changes to this bug.