Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: systemd-timesyncd is unable to read the systemd-networkd state files. These denials are in addition to the ones fixed in bug 1646202... Version-Release number of selected component (if applicable): selinux-policy-targeted-3.14.2-42.fc29 systemd-udev-239-6.git9f3aed1.fc29 How reproducible: When running systemd-timesyncd and systemd-networkd Relevant ausearch output: type=PROCTITLE msg=audit(11/24/2018 22:54:07.660:78) : proctitle=/usr/lib/systemd/systemd-timesyncd type=PATH msg=audit(11/24/2018 22:54:07.660:78) : item=0 name=/run/systemd/netif/links/ inode=13816 dev=00:16 mode=dir,755 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 type=CWD msg=audit(11/24/2018 22:54:07.660:78) : cwd=/ type=SYSCALL msg=audit(11/24/2018 22:54:07.660:78) : arch=x86_64 syscall=inotify_add_watch success=yes exit=1 a0=0xb a1=0x7f41a3a5e6af a2=0x280 a3=0x7ffe4c00bccc items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:07.660:78) : avc: denied { read } for pid=512 comm=systemd-timesyn name=links dev="tmpfs" ino=13816 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=dir permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:07.663:79) : proctitle=/usr/lib/systemd/systemd-timesyncd type=PATH msg=audit(11/24/2018 22:54:07.663:79) : item=0 name=/run/systemd/netif/state inode=16021 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 type=CWD msg=audit(11/24/2018 22:54:07.663:79) : cwd=/ type=SYSCALL msg=audit(11/24/2018 22:54:07.663:79) : arch=x86_64 syscall=openat success=yes exit=12 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:07.663:79) : avc: denied { open } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2018 22:54:07.663:79) : avc: denied { read } for pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:07.664:80) : proctitle=/usr/lib/systemd/systemd-timesyncd type=SYSCALL msg=audit(11/24/2018 22:54:07.664:80) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xc a1=0x7ffe4c00ba00 a2=0x7ffe4c00ba00 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:07.664:80) : avc: denied { getattr } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=16021 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:09.045:104) : proctitle=/usr/lib/systemd/systemd-timesyncd type=PATH msg=audit(11/24/2018 22:54:09.045:104) : item=0 name=/run/systemd/netif/state inode=19181 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 type=CWD msg=audit(11/24/2018 22:54:09.045:104) : cwd=/ type=SYSCALL msg=audit(11/24/2018 22:54:09.045:104) : arch=x86_64 syscall=openat success=yes exit=12 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:09.045:104) : avc: denied { open } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2018 22:54:09.045:104) : avc: denied { read } for pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:09.047:105) : proctitle=/usr/lib/systemd/systemd-timesyncd type=SYSCALL msg=audit(11/24/2018 22:54:09.047:105) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xc a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:09.047:105) : avc: denied { getattr } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=19181 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:15.431:123) : proctitle=/usr/lib/systemd/systemd-timesyncd type=PATH msg=audit(11/24/2018 22:54:15.431:123) : item=0 name=/run/systemd/netif/state inode=20127 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 type=CWD msg=audit(11/24/2018 22:54:15.431:123) : cwd=/ type=SYSCALL msg=audit(11/24/2018 22:54:15.431:123) : arch=x86_64 syscall=openat success=yes exit=15 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:15.431:123) : avc: denied { open } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2018 22:54:15.431:123) : avc: denied { read } for pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:15.431:124) : proctitle=/usr/lib/systemd/systemd-timesyncd type=SYSCALL msg=audit(11/24/2018 22:54:15.431:124) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xf a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:15.431:124) : avc: denied { getattr } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20127 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:26.033:125) : proctitle=/usr/lib/systemd/systemd-timesyncd type=PATH msg=audit(11/24/2018 22:54:26.033:125) : item=0 name=/run/systemd/netif/state inode=20374 dev=00:16 mode=file,644 ouid=systemd-network ogid=systemd-network rdev=00:00 obj=system_u:object_r:systemd_networkd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 type=CWD msg=audit(11/24/2018 22:54:26.033:125) : cwd=/ type=SYSCALL msg=audit(11/24/2018 22:54:26.033:125) : arch=x86_64 syscall=openat success=yes exit=15 a0=0xffffff9c a1=0x7f41a3a5e67a a2=O_RDONLY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:26.033:125) : avc: denied { open } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2018 22:54:26.033:125) : avc: denied { read } for pid=512 comm=systemd-timesyn name=state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2018 22:54:26.033:126) : proctitle=/usr/lib/systemd/systemd-timesyncd type=SYSCALL msg=audit(11/24/2018 22:54:26.033:126) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0xf a1=0x7ffe4c00b920 a2=0x7ffe4c00b920 a3=0x0 items=0 ppid=1 pid=512 auid=unset uid=systemd-timesync gid=systemd-timesync euid=systemd-timesync suid=systemd-timesync fsuid=systemd-timesync egid=systemd-timesync sgid=systemd-timesync fsgid=systemd-timesync tty=(none) ses=unset comm=systemd-timesyn exe=/usr/lib/systemd/systemd-timesyncd subj=system_u:system_r:systemd_timedated_t:s0 key=(null) type=AVC msg=audit(11/24/2018 22:54:26.033:126) : avc: denied { getattr } for pid=512 comm=systemd-timesyn path=/run/systemd/netif/state dev="tmpfs" ino=20374 scontext=system_u:system_r:systemd_timedated_t:s0 tcontext=system_u:object_r:systemd_networkd_var_run_t:s0 tclass=file permissive=1 ---- These boil down to the following needed rules: allow systemd_timedated_t systemd_networkd_var_run_t:dir read; allow systemd_timedated_t systemd_networkd_var_run_t:file { getattr open read };
commit 1e340794f40830e16753caafb53c8f5349dd7276 Author: Lukas Vrabec <lvrabec> Date: Tue Nov 6 16:14:15 2018 +0100 Update systemd_timedated_t domain to allow create own pid files/access init_var_lib_t files and read dbus files BZ(1646202)
Great, looks like these additional issues are resolved with selinux-policy-3.14.2-44.fc29.noarch Closing. Thanks!