Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: When a local policy module was created to grant a particular permission previously reported as denied by audit, sealert reports: Invalid AVC allowed in current policy which is confusing and misleads troubleshooting. This error message is not explained neither in the sealert manual page nor in documentation. Version-Release number of selected component (if applicable): setroubleshoot-3.3.18-1.fc29.x86_64 How reproducible: always Steps to Reproduce: 1. Trigger an AVC chronyc tracking > /root/avctest 2. Create and insert a custom policy module to grant the permission echo '(allow chronyc_t admin_home_t (file (write)))' > /tmp/chronyc-write.cil semodule -i /tmp/chronyc-write.cil 3. Run sealert sealert -a /var/log/audit/audit.log > /tmp/sealert.txt /usr/bin/sealert:32: DeprecationWarning: Importing dbus.glib to use the GLib main loop with dbus-python is deprecated. Instead, use this sequence: from dbus.mainloop.glib import DBusGMainLoop DBusGMainLoop(set_as_default=True) import dbus.glib type=AVC msg=audit(1543339233.655:381): avc: denied { write } for pid=15235 comm="chronyc" path="/root/avctest" dev="vda1" ino=1747 scontext=unconfined_u:unconfined_r:chronyc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file permissive=0 **** Invalid AVC allowed in current policy *** Actual results: A misleading error message appears on stderr. Expected results: The error message is comprehensive or none. Additional info:
This bug appears to have been reported against 'rawhide' during the Fedora 32 development cycle. Changing version to 32.
* Tue Apr 21 2020 Vit Mojzis <vmojzis> - 3.3.23-1 - browser: Check return value of Gdk.Screen().get_default() - Improve and unify error messages - setroubleshoot.util: Catch exceptions from sepolicy import - Add dpkg support - Do not refer to hardcoded selinux-policy rpm in signature - Make date/time format locale specific - Improve speed of plugin evaluation