Bug 1653050 - SELinux is preventing systemd-timesyncd access to /run/systemd/netif state files
Summary: SELinux is preventing systemd-timesyncd access to /run/systemd/netif state files
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 29
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-11-25 07:28 UTC by Scott Shambarger
Modified: 2020-05-12 08:58 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2019-01-08 20:14:43 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Scott Shambarger 2018-11-25 07:28:16 UTC
Description of problem:
systemd-timesyncd is unable to read the systemd-networkd state files.

These denials are in addition to the ones fixed in bug 1646202...

Version-Release number of selected component (if applicable):
selinux-policy-targeted-3.14.2-42.fc29
systemd-udev-239-6.git9f3aed1.fc29

How reproducible:
When running systemd-timesyncd and systemd-networkd

Relevant ausearch output:

type=PROCTITLE msg=audit(11/24/2018 22:54:07.660:78) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=PATH msg=audit(11/24/2018 22:54:07.660:78) : item=0 name=/run/systemd/netif/links/ inode=13816 dev=00:16 mode=dir,755 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
type=CWD msg=audit(11/24/2018 22:54:07.660:78) : cwd=/ 
type=SYSCALL msg=audit(11/24/2018 22:54:07.660:78) : arch=x86_64 syscall=inotify_add_watch success=yes exit=1 a0=0xb a1=0x7f41a3a5e6af a2=0x280 a3=0x7ffe4c00bccc items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:07.660:78) : avc:  denied  { read } for  pid=512 comm=systemd-timesyn name=links dev="tmpfs" ino=13816 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=dir permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:07.663:79) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=PATH msg=audit(11/24/2018 22:54:07.663:79) : item=0 name=/run/systemd/netif/state inode=16021 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
type=CWD msg=audit(11/24/2018 22:54:07.663:79) : cwd=/ 
type=SYSCALL msg=audit(11/24/2018 22:54:07.663:79) : arch=x86_64 syscall=openat success=yes exit=12 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:07.663:79) : avc:  denied  { open } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2018 22:54:07.663:79) : avc:  denied  { read } for  pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:07.664:80) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=SYSCALL msg=audit(11/24/2018 22:54:07.664:80) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xc a1=0x7ffe4c00ba00 a2=0x7ffe4c00ba00 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:07.664:80) : avc:  denied  { getattr } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:09.045:104) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=PATH msg=audit(11/24/2018 22:54:09.045:104) : item=0 name=/run/systemd/netif/state inode=19181 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
type=CWD msg=audit(11/24/2018 22:54:09.045:104) : cwd=/ 
type=SYSCALL msg=audit(11/24/2018 22:54:09.045:104) : arch=x86_64 syscall=openat success=yes exit=12 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:09.045:104) : avc:  denied  { open } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2018 22:54:09.045:104) : avc:  denied  { read } for  pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:09.047:105) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=SYSCALL msg=audit(11/24/2018 22:54:09.047:105) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xc a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:09.047:105) : avc:  denied  { getattr } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:15.431:123) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=PATH msg=audit(11/24/2018 22:54:15.431:123) : item=0 name=/run/systemd/netif/state inode=20127 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
type=CWD msg=audit(11/24/2018 22:54:15.431:123) : cwd=/ 
type=SYSCALL msg=audit(11/24/2018 22:54:15.431:123) : arch=x86_64 syscall=openat success=yes exit=15 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:15.431:123) : avc:  denied  { open } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2018 22:54:15.431:123) : avc:  denied  { read } for  pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:15.431:124) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=SYSCALL msg=audit(11/24/2018 22:54:15.431:124) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xf a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:15.431:124) : avc:  denied  { getattr } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:26.033:125) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=PATH msg=audit(11/24/2018 22:54:26.033:125) : item=0 name=/run/systemd/netif/state inode=20374 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 
type=CWD msg=audit(11/24/2018 22:54:26.033:125) : cwd=/ 
type=SYSCALL msg=audit(11/24/2018 22:54:26.033:125) : arch=x86_64 syscall=openat success=yes exit=15 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:26.033:125) : avc:  denied  { open } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2018 22:54:26.033:125) : avc:  denied  { read } for  pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2018 22:54:26.033:126) : proctitle=/usr/lib/systemd/systemd-timesyncd 
type=SYSCALL msg=audit(11/24/2018 22:54:26.033:126) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xf a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) 
type=AVC msg=audit(11/24/2018 22:54:26.033:126) : avc:  denied  { getattr } for  pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 
----

These boil down to the following needed rules:

allow systemd_timedated_t systemd_networkd_var_run_t:dir read;
allow systemd_timedated_t systemd_networkd_var_run_t:file { getattr open read };

Comment 1 Lukas Vrabec 2019-01-08 15:57:40 UTC
commit 1e340794f40830e16753caafb53c8f5349dd7276
Author: Lukas Vrabec <lvrabec>
Date:   Tue Nov 6 16:14:15 2018 +0100

    Update systemd_timedated_t domain to allow create own pid files/access init_var_lib_t files and read dbus files BZ(1646202)

Comment 2 Scott Shambarger 2019-01-08 20:14:43 UTC
Great, looks like these additional issues are resolved with selinux-policy-3.14.2-44.fc29.noarch

Closing.  Thanks!


Note You need to log in before you can comment on or make changes to this bug.