Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: "systemd-run --system --pty bash -i" is denied by selinux. Version-Release number of selected component (if applicable): selinux-policy-targeted-3.14.2-40.fc29.noarch systemd-239-6.git9f3aed1.fc29.x86_64 How reproducible: Steps to Reproduce: 1. run: systemd-run --system --pty bash -i Actual results: $ systemd-run --system --pty bash -i Running as unit: run-u40913.service Press ^] three times within 1s to disconnect TTY. $ $ sudo journalctl UNIT=run-u40913.service -- Logs begin at Thu 2018-10-18 12:13:12 EEST, end at Tue 2018-11-06 20:54:28 EET. -- Nov 06 20:52:28 workstation systemd[1]: Started /usr/bin/bash -i. Nov 06 20:52:28 workstation systemd[15662]: run-u40913.service: Failed to set up standard input: Permission denied Nov 06 20:52:28 workstation systemd[15662]: run-u40913.service: Failed at step STDIN spawning /usr/bin/bash: Permission denied Nov 06 20:52:28 workstation systemd[1]: run-u40913.service: Main process exited, code=exited, status=208/STDIN Nov 06 20:52:28 workstation systemd[1]: run-u40913.service: Failed with result 'exit-code'. Expected results: $ systemd-run --system --pty bash -i Running as unit: run-u40962.service Press ^] three times within 1s to disconnect TTY. [root@workstation /]# exit $ Additional info: Expected results achieved by using this local module: module my-systemd-run-pty 1.0; require { type user_devpts_t; type init_t; class chr_file { open setattr }; } allow init_t user_devpts_t:chr_file { open setattr }; audit.lines: type=AVC msg=audit(1541530348.901:2145): avc: denied { open } for pid=15662 comm="(bash)" path="/dev/pts/2" dev="devpts" ino=5 scontext=system_u:system_r:init_t:s0 tcontext=unconfined_u:object_r:user_devpts_t:s0 tclass=chr_file permissive=0 type=AVC msg=audit(1541527674.886:1886): avc: denied { setattr } for pid=8162 comm="(bash)" name="2" dev="devpts" ino=5 scontext=system_u:system_r:init_t:s0 tcontext=unconfined_u:object_r:user_devpts_t:s0 tclass=chr_file permissive=0
*** Bug 1656994 has been marked as a duplicate of this bug. ***
commit a7fb5bc9b4591c8c6ee3c58f394b5c9818ccab28 (HEAD -> rawhide) Author: Lukas Vrabec <lvrabec> Date: Wed Jan 9 17:38:20 2019 +0100 Make workin: systemd-run --system --pty bash BZ(1647162)
selinux-policy-3.14.2-46.fc29 has been submitted as an update to Fedora 29. https://bodhi.fedoraproject.org/updates/FEDORA-2019-6a20cfef61
selinux-policy-3.14.2-46.fc29 has been pushed to the Fedora 29 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2019-6a20cfef61
selinux-policy-3.14.2-46.fc29 has been pushed to the Fedora 29 stable repository. If problems still persist, please make note of it in this bug report.