Bug 1653833 - Invalid AVC allowed in current policy reported by sealert
Summary: Invalid AVC allowed in current policy reported by sealert
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: setroubleshoot
Version: 32
Hardware: All
OS: Linux
unspecified
low
Target Milestone: ---
Assignee: Petr Lautrbach
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks: 1763982
TreeView+ depends on / blocked
 
Reported: 2018-11-27 17:38 UTC by Zdenek Pytela
Modified: 2020-06-23 19:04 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
: 1763982 (view as bug list)
Environment:
Last Closed: 2020-06-23 19:04:46 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Zdenek Pytela 2018-11-27 17:38:35 UTC
Description of problem:
When a local policy module was created to grant a particular permission
previously reported as denied by audit, sealert reports:

Invalid AVC allowed in current policy

which is confusing and misleads troubleshooting. This error message is not explained neither in the sealert manual page nor in documentation.

Version-Release number of selected component (if applicable):
setroubleshoot-3.3.18-1.fc29.x86_64

How reproducible:
always

Steps to Reproduce:
1. Trigger an AVC
chronyc tracking > /root/avctest

2. Create and insert a custom policy module to grant the permission
echo '(allow chronyc_t admin_home_t (file (write)))' > /tmp/chronyc-write.cil
semodule -i /tmp/chronyc-write.cil

3. Run sealert
sealert -a /var/log/audit/audit.log > /tmp/sealert.txt
/usr/bin/sealert:32: DeprecationWarning: Importing dbus.glib to use the GLib main loop with dbus-python is deprecated.
Instead, use this sequence:

    from dbus.mainloop.glib import DBusGMainLoop

    DBusGMainLoop(set_as_default=True)

  import dbus.glib

 type=AVC msg=audit(1543339233.655:381): avc:  denied  { write } for  pid=15235 comm="chronyc" path="/root/avctest" dev="vda1" ino=1747 scontext=unconfined_u:unconfined_r:chronyc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file permissive=0
 
**** Invalid AVC allowed in current policy ***


Actual results:
A misleading error message appears on stderr.

Expected results:
The error message is comprehensive or none.

Additional info:

Comment 3 Ben Cotton 2020-02-11 15:43:06 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 32 development cycle.
Changing version to 32.

Comment 5 Petr Lautrbach 2020-06-23 19:04:46 UTC
* Tue Apr 21 2020 Vit Mojzis <vmojzis> - 3.3.23-1
- browser: Check return value of Gdk.Screen().get_default()
- Improve and unify error messages
- setroubleshoot.util: Catch exceptions from sepolicy import
- Add dpkg support
- Do not refer to hardcoded selinux-policy rpm in signature
- Make date/time format locale specific
- Improve speed of plugin evaluation


Note You need to log in before you can comment on or make changes to this bug.