Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing restorecon from 'write' accesses on the file /var/log/pcp/pmlogger/pmlogger_daily-K.log. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that restorecon should be allowed write access on the pmlogger_daily-K.log file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'restorecon' --raw | audit2allow -M my-restorecon # semodule -X 300 -i my-restorecon.pp Additional Information: Source Context unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c102 3 Target Context unconfined_u:object_r:pcp_log_t:s0 Target Objects /var/log/pcp/pmlogger/pmlogger_daily-K.log [ file ] Source restorecon Source Path restorecon Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.14.2-49.fc29.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.20.13-200.fc29.x86_64 #1 SMP Wed Feb 27 19:42:55 UTC 2019 x86_64 x86_64 Alert Count 2 First Seen 2019-03-15 10:20:21 CET Last Seen 2019-03-15 10:20:21 CET Local ID acdd7178-64c1-4880-b27e-2c198ff1f66f Raw Audit Messages type=AVC msg=audit(1552641621.910:1143458): avc: denied { write } for pid=9878 comm="restorecon" path="/var/log/pcp/pmlogger/pmlogger_daily-K.log" dev="dm-1" ino=137007897 scontext=unconfined_u:unconfined_r:setfiles_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:pcp_log_t:s0 tclass=file permissive=0 Hash: restorecon,setfiles_t,pcp_log_t,file,write Version-Release number of selected component: selinux-policy-3.14.2-49.fc29.noarch Additional info: component: selinux-policy reporter: libreport-2.10.0 hashmarkername: setroubleshoot kernel: 4.20.13-200.fc29.x86_64 type: libreport
*** Bug 1689192 has been marked as a duplicate of this bug. ***
Hi, I'm not really sure whats going on here. Command restorecon should not require "write" permission. Are you able to reproduce it? Thanks, Lukas.
I'm getting the same issue. Fedora Server 30 + cockpit-pcp. Audit log: ``` type=AVC msg=audit(1556179397.184:187735): avc: denied { write } for pid=15593 comm="restorecon" path="/var/log/pcp/pmlogger/pmlogger_daily-K.log" dev="dm-3" ino=30254911 scontext=unconfined_u:unconfined_r:setfiles_t:s0 tcontext=unconfined_u:object_r:pcp_log_t:s0 tclass=file permissive=0 ``` Log entries (probably related to each other) in order of appearance: 1) ``` cockpit-ws Thu Apr 25 2019 12:02:40 GMT+0200 (CEST) couldn't read from connection: Peer failed to perform TLS handshake COCKPIT_DOMAIN cockpit-protocol PRIORITY 4 SYSLOG_IDENTIFIER cockpit-ws _BOOT_ID 342482bb3a77450baf174adfcd3a7bb7 _CAP_EFFECTIVE 0 _CMDLINE /usr/libexec/cockpit-ws _COMM cockpit-ws _EXE /usr/libexec/cockpit-ws _GID 991 _HOSTNAME examplecom _MACHINE_ID d27af624caa149cfa0852465e4d747f4 _PID 14008 _SELINUX_CONTEXT system_u:system_r:cockpit_ws_t:s0 _SOURCE_REALTIME_TIMESTAMP 1556186560929027 _SYSTEMD_CGROUP /system.slice/cockpit.service _SYSTEMD_INVOCATION_ID 046ced2c79f043bc95b21f10e44f7c24 _SYSTEMD_SLICE system.slice _SYSTEMD_UNIT cockpit.service _TRANSPORT journal _UID 995 __CURSOR s=50ad1f15b527451e9608a6f549b5a9f0;i=5fd46;b=342482bb3a77450baf174adfcd3a7bb7;m=310b5b33a1;t=58757eb2b1d4b;x=2ed075586484f937 __MONOTONIC_TIMESTAMP 210643923873 __REALTIME_TIMESTAMP 1556186560929099 ``` 2) ``` systemd Thu Apr 25 2019 12:07:47 GMT+0200 (CEST) packagekit.service: Main process exited, code=killed, status=15/TERM CODE_FILE ../src/core/unit.c CODE_FUNC unit_log_process_exit CODE_LINE 5525 COMMAND ExecStart EXIT_CODE killed EXIT_STATUS 15 INVOCATION_ID a85fac213da14c0c82adfe0d32cc44a1 MESSAGE_ID 98e322203f7a4ed290d09fe03c09fe15 PRIORITY 4 SYSLOG_FACILITY 3 SYSLOG_IDENTIFIER systemd UNIT packagekit.service _BOOT_ID 342482bb3a77450baf174adfcd3a7bb7 _CAP_EFFECTIVE 3fffffffff _CMDLINE /usr/lib/systemd/systemd --switched-root --system --deserialize 33 _COMM systemd _EXE /usr/lib/systemd/systemd _GID 0 _HOSTNAME example.com _MACHINE_ID d27af624caa149cfa0852465e4d747f4 _PID 1 _SELINUX_CONTEXT system_u:system_r:init_t:s0 _SOURCE_REALTIME_TIMESTAMP 1556186867031696 _SYSTEMD_CGROUP /init.scope _SYSTEMD_SLICE -.slice _SYSTEMD_UNIT init.scope _TRANSPORT journal _UID 0 __CURSOR s=50ad1f15b527451e9608a6f549b5a9f0;i=5fde7;b=342482bb3a77450baf174adfcd3a7bb7;m=311d99f50d;t=58757fd69deb7;x=d87105937b8f8135 __MONOTONIC_TIMESTAMP 210950026509 __REALTIME_TIMESTAMP 1556186867031735 ``` 3) ``` kernel Thu Apr 25 2019 12:10:21 GMT+0200 (CEST) show_signal_msg: 32 callbacks suppressed PRIORITY 4 SYSLOG_FACILITY 0 SYSLOG_IDENTIFIER kernel _BOOT_ID 342482bb3a77450baf174adfcd3a7bb7 _HOSTNAME example.com _MACHINE_ID d27af624caa149cfa0852465e4d747f4 _SOURCE_MONOTONIC_TIMESTAMP 211105393578 _TRANSPORT kernel __CURSOR s=50ad1f15b527451e9608a6f549b5a9f0;i=5fe3b;b=342482bb3a77450baf174adfcd3a7bb7;m=3126d2126b;t=5875806a1fc16;x=f31cc2eedc2a1ec8 __MONOTONIC_TIMESTAMP 211104698987 __REALTIME_TIMESTAMP 1556187021704214 ``` 4) ``` systemd-coredump Thu Apr 25 2019 12:10:22 GMT+0200 (CEST) Process 23406 (cockpit-pcp) of user 1000 dumped core. CODE_FILE ../src/coredump/coredump.c CODE_FUNC submit_coredump CODE_LINE 834 COREDUMP_CGROUP /user.slice/user-1000.slice/session-12.scope COREDUMP_CMDLINE /usr/libexec/cockpit-pcp COREDUMP_COMM cockpit-pcp COREDUMP_CWD /run/user/1000 COREDUMP_ENVIRON SSH_AUTH_SOCK=/tmp/ssh-7PUT0GtNkEDh/agent.14018 SSH_AGENT_PID=14019 PWD=/ XDG_SESSION_TYPE=web COCKPIT_REMOTE_PEER=::1 HOME=/home/zalex LANG=en_GB.UTF-8 XDG_SESSION_CLASS=user LESSOPEN=||/usr/bin/lesspipe.sh %s SHLVL=0 XDG_SESSION_ID=12 XDG_RUNTIME_DIR=/run/user/1000 PATH=/home/zalex/.local/bin:/home/zalex/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin DBUS_SESSION_BUS_ADDRESS=unix:path=/run/user/1000/bus GSETTINGS_BACKEND=memory USER=zalex SHELL=/bin/bash COREDUMP_EXE /usr/libexec/cockpit-pcp COREDUMP_GID 1000 COREDUMP_HOSTNAME example.com COREDUMP_OPEN_FDS 0:socket:[1510374] pos: 0 flags: 04002 mnt_id: 9 1:socket:[1513312] pos: 0 flags: 02 mnt_id: 9 2:socket:[1513312] pos: 0 flags: 02 mnt_id: 9 3:socket:[1513312] pos: 0 flags: 02000002 mnt_id: 9 4:socket:[1510374] pos: 0 flags: 04002 mnt_id: 9 5:anon_inode:[eventfd] pos: 0 flags: 02004002 mnt_id: 13 eventfd-count: 0 6:anon_inode:[eventfd] pos: 0 flags: 02004002 mnt_id: 13 eventfd-count: 1 7:/var/lib/sss/mc/passwd pos: 0 flags: 02100000 mnt_id: 95 8:/var/lib/pcp/pmdas/linux/help.dir pos: 12 flags: 0100000 mnt_id: 95 9:/var/lib/pcp/pmdas/linux/help.pag pos: 0 flags: 0100000 mnt_id: 95 10:/var/lib/pcp/pmdas/jbd2/help.dir pos: 12 flags: 0100000 mnt_id: 95 11:/var/lib/pcp/pmdas/jbd2/help.pag pos: 0 flags: 0100000 mnt_id: 95 12:/proc/stat pos: 4801 flags: 0100000 mnt_id: 21 13:socket:[1516690] pos: 0 flags: 02 mnt_id: 9 COREDUMP_OWNER_UID 1000 COREDUMP_PID 23406 COREDUMP_PROC_CGROUP 11:memory:/user.slice/user-1000.slice/session-12.scope 10:pids:/user.slice/user-1000.slice/session-12.scope 9:cpuset:/ 8:devices:/user.slice 7:cpu,cpuacct:/ 6:freezer:/ 5:perf_event:/ 4:net_cls,net_prio:/ 3:blkio:/user.slice 2:hugetlb:/ 1:name=systemd:/user.slice/user-1000.slice/session-12.scope 0::/user.slice/user-1000.slice/session-12.scope COREDUMP_PROC_LIMITS Limit Soft Limit Hard Limit Units Max cpu time unlimited unlimited seconds Max file size unlimited unlimited bytes Max data size unlimited unlimited bytes Max stack size 8388608 unlimited bytes Max core file size 0 unlimited bytes Max resident set unlimited unlimited bytes Max processes 127606 127606 processes Max open files 1024 524288 files Max locked memory 65536 65536 bytes Max address space unlimited unlimited bytes Max file locks unlimited unlimited locks Max pending signals 127606 127606 signals Max msgqueue size 819200 819200 bytes Max nice priority 0 0 Max realtime priority 0 0 Max realtime timeout unlimited unlimited us COREDUMP_PROC_MAPS [no data] COREDUMP_PROC_MOUNTINFO 20 95 0:20 / /sys rw,nosuid,nodev,noexec,relatime shared:2 - sysfs sysfs rw,seclabel 21 95 0:4 / /proc rw,nosuid,nodev,noexec,relatime shared:26 - proc proc rw 22 95 0:6 / /dev rw,nosuid shared:22 - devtmpfs devtmpfs rw,seclabel,size=16333648k,nr_inodes=4083412,mode=755 23 20 0:7 / /sys/kernel/security rw,nosuid,nodev,noexec,relatime shared:3 - securityfs securityfs rw 24 22 0:21 / /dev/shm rw,nosuid,nodev shared:23 - tmpfs tmpfs rw,seclabel 25 22 0:22 / /dev/pts rw,nosuid,noexec,relatime shared:24 - devpts devpts rw,seclabel,gid=5,mode=620,ptmxmode=000 26 95 0:23 / /run rw,nosuid,nodev shared:25 - tmpfs tmpfs rw,seclabel,mode=755 27 20 0:24 / /sys/fs/cgroup ro,nosuid,nodev,noexec shared:4 - tmpfs tmpfs ro,seclabel,mode=755 28 27 0:25 / /sys/fs/cgroup/unified rw,nosuid,nodev,noexec,relatime shared:5 - cgroup2 cgroup2 rw,seclabel,nsdelegate 29 27 0:26 / /sys/fs/cgroup/systemd rw,nosuid,nodev,noexec,relatime shared:6 - cgroup cgroup rw,seclabel,xattr,name=systemd 30 20 0:27 / /sys/fs/pstore rw,nosuid,nodev,noexec,relatime shared:17 - pstore pstore rw,seclabel 31 20 0:28 / /sys/firmware/efi/efivars rw,nosuid,nodev,noexec,relatime shared:18 - efivarfs efivarfs rw 32 20 0:29 / /sys/fs/bpf rw,nosuid,nodev,noexec,relatime shared:19 - bpf bpf rw,mode=700 33 27 0:30 / /sys/fs/cgroup/hugetlb rw,nosuid,nodev,noexec,relatime shared:7 - cgroup cgroup rw,seclabel,hugetlb 34 27 0:31 / /sys/fs/cgroup/blkio rw,nosuid,nodev,noexec,relatime shared:8 - cgroup cgroup rw,seclabel,blkio 35 27 0:32 / /sys/fs/cgroup/net_cls,net_prio rw,nosuid,nodev,noexec,relatime shared:9 - cgroup cgroup rw,seclabel,net_cls,net_prio 36 27 0:33 / /sys/fs/cgroup/perf_event rw,nosuid,nodev,noexec,relatime shared:10 - cgroup cgroup rw,seclabel,perf_event 37 27 0:34 / /sys/fs/cgroup/freezer rw,nosuid,nodev,noexec,relatime shared:11 - cgroup cgroup rw,seclabel,freezer 38 27 0:35 / /sys/fs/cgroup/cpu,cpuacct rw,nosuid,nodev,noexec,relatime shared:12 - cgroup cgroup rw,seclabel,cpu,cpuacct 39 27 0:36 / /sys/fs/cgroup/devices rw,nosuid,nodev,noexec,relatime shared:13 - cgroup cgroup rw,seclabel,devices 40 27 0:37 / /sys/fs/cgroup/cpuset rw,nosuid,nodev,noexec,relatime shared:14 - cgroup cgroup rw,seclabel,cpuset 41 27 0:38 / /sys/fs/cgroup/pids rw,nosuid,nodev,noexec,relatime shared:15 - cgroup cgroup rw,seclabel,pids 42 27 0:39 / /sys/fs/cgroup/memory rw,nosuid,nodev,noexec,relatime shared:16 - cgroup cgroup rw,seclabel,memory 91 20 0:40 / /sys/kernel/config rw,relatime shared:20 - configfs configfs rw 95 0 253:3 / / rw,relatime shared:1 - xfs /dev/mapper/f30-root rw,seclabel,attr2,inode64,sunit=128,swidth=128,noquota 43 20 0:19 / /sys/fs/selinux rw,relatime shared:21 - selinuxfs selinuxfs rw 44 21 0:42 / /proc/sys/fs/binfmt_misc rw,relatime shared:27 - autofs systemd-1 rw,fd=31,pgrp=1,timeout=0,minproto=5,maxproto=5,direct,pipe_ino=17813 45 22 0:18 / /dev/mqueue rw,relatime shared:28 - mqueue mqueue rw,seclabel 46 20 0:8 / /sys/kernel/debug rw,relatime shared:29 - debugfs debugfs rw,seclabel 47 22 0:43 / /dev/hugepages rw,relatime shared:30 - hugetlbfs hugetlbfs rw,seclabel,pagesize=2M 48 20 0:44 / /sys/fs/fuse/connections rw,relatime shared:31 - fusectl fusectl rw 49 95 0:45 / /tmp rw,nosuid,nodev shared:32 - tmpfs tmpfs rw,seclabel 118 95 259:2 / /boot rw,relatime shared:65 - ext4 /dev/nvme0n1p2 rw,seclabel 121 118 259:1 / /boot/efi rw,relatime shared:67 - vfat /dev/nvme0n1p1 rw,fmask=0077,dmask=0077,codepage=437,iocharset=ascii,shortname=winnt,errors=remount-ro 264 95 0:46 / /var/lib/nfs/rpc_pipefs rw,relatime shared:104 - rpc_pipefs sunrpc rw 510 26 0:49 / /run/user/1000 rw,nosuid,nodev,relatime shared:286 - tmpfs tmpfs rw,seclabel,size=3270004k,mode=700,uid=1000,gid=1000 857 46 0:11 / /sys/kernel/debug/tracing rw,relatime shared:467 - tracefs tracefs rw,seclabel COREDUMP_PROC_STATUS Name: cockpit-pcp Umask: 0022 State: S (sleeping) Tgid: 23406 Ngid: 0 Pid: 23406 PPid: 14036 TracerPid: 0 Uid: 1000 1000 1000 1000 Gid: 1000 1000 1000 1000 FDSize: 64 Groups: 10 1000 NStgid: 23406 NSpid: 23406 NSpgid: 14008 NSsid: 14008 VmPeak: 159720 kB VmSize: 104708 kB VmLck: 0 kB VmPin: 0 kB VmHWM: 11868 kB VmRSS: 11868 kB RssAnon: 2888 kB RssFile: 8980 kB RssShmem: 0 kB VmData: 10720 kB VmStk: 132 kB VmExe: 140 kB VmLib: 11888 kB VmPTE: 96 kB VmSwap: 0 kB HugetlbPages: 0 kB CoreDumping: 1 THP_enabled: 1 Threads: 2 SigQ: 0/127606 SigPnd: 0000000000000000 ShdPnd: 0000000000000000 SigBlk: 0000000000000000 SigIgn: 0000000000001000 SigCgt: 0000000180004000 CapInh: 0000000000000000 CapPrm: 0000000000000000 CapEff: 0000000000000000 CapBnd: 0000003fffffffff CapAmb: 0000000000000000 NoNewPrivs: 0 Seccomp: 0 Speculation_Store_Bypass: thread vulnerable Cpus_allowed: ff Cpus_allowed_list: 0-7 Mems_allowed: 00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000001 Mems_allowed_list: 0 voluntary_ctxt_switches: 33675 nonvoluntary_ctxt_switches: 1316 COREDUMP_RLIMIT 0 COREDUMP_ROOT / COREDUMP_SESSION 12 COREDUMP_SIGNAL 11 COREDUMP_SIGNAL_NAME SIGSEGV COREDUMP_SLICE user-1000.slice COREDUMP_TIMESTAMP 1556187021000000 COREDUMP_UID 1000 COREDUMP_UNIT session-12.scope MESSAGE_ID fc2e22bc6ee647b6b90729ab34a250b1 PRIORITY 2 SYSLOG_IDENTIFIER systemd-coredump _BOOT_ID 342482bb3a77450baf174adfcd3a7bb7 _CAP_EFFECTIVE 3ff7fcffff _COMM systemd-coredum _GID 0 _HOSTNAME example.com _MACHINE_ID d27af624caa149cfa0852465e4d747f4 _PID 27616 _SELINUX_CONTEXT system_u:system_r:systemd_coredump_t:s0 _SOURCE_REALTIME_TIMESTAMP 1556187022006694 _SYSTEMD_CGROUP /system.slice/system-systemd\x2dcoredump.slice/systemd-coredump _SYSTEMD_INVOCATION_ID b81da815003f43e994dae61b53a3c9f8 _SYSTEMD_SLICE system-systemd\x2dcoredump.slice _SYSTEMD_UNIT systemd-coredump _TRANSPORT journal _UID 0 __CURSOR s=50ad1f15b527451e9608a6f549b5a9f0;i=5fe4a;b=342482bb3a77450baf174adfcd3a7bb7;m=3126d6b24a;t=5875806a69bf5;x=3ce5443cb32dd054 __MONOTONIC_TIMESTAMP 211105002058 __REALTIME_TIMESTAMP 1556187022007285 ``` 5) ``` cockpit-bridge Thu Apr 25 2019 12:10:22 GMT+0200 (CEST) /usr/libexec/cockpit-pcp: bridge was killed: 11 COCKPIT_DOMAIN cockpit-bridge PRIORITY 4 SYSLOG_IDENTIFIER cockpit-bridge _AUDIT_LOGINUID 1000 _AUDIT_SESSION 12 _BOOT_ID 342482bb3a77450baf174adfcd3a7bb7 _CAP_EFFECTIVE 0 _CMDLINE cockpit-bridge _COMM cockpit-bridge _EXE /usr/bin/cockpit-bridge _GID 1000 _HOSTNAME example.com _MACHINE_ID d27af624caa149cfa0852465e4d747f4 _PID 14036 _SELINUX_CONTEXT unconfined_u:unconfined_r:unconfined_t:s0 _SOURCE_REALTIME_TIMESTAMP 1556187022008221 _SYSTEMD_CGROUP /user.slice/user-1000.slice/session-12.scope _SYSTEMD_INVOCATION_ID 4fe12703fb7a48cd9f24fbad3d7f43db _SYSTEMD_OWNER_UID 1000 _SYSTEMD_SESSION 12 _SYSTEMD_SLICE user-1000.slice _SYSTEMD_UNIT session-12.scope _SYSTEMD_USER_SLICE -.slice _TRANSPORT journal _UID 1000 __CURSOR s=e5395f1a34a74348963043c8c55e2d84;i=5fe4d;b=342482bb3a77450baf174adfcd3a7bb7;m=3126d6d1c3;t=5875806a6bb6d;x=d934c9d1be97fd44 __MONOTONIC_TIMESTAMP 211105010115 __REALTIME_TIMESTAMP 1556187022015341 ```
*** Bug 1747488 has been marked as a duplicate of this bug. ***
This message is a reminder that Fedora 29 is nearing its end of life. Fedora will stop maintaining and issuing updates for Fedora 29 on 2019-11-26. It is Fedora's policy to close all bug reports from releases that are no longer maintained. At that time this bug will be closed as EOL if it remains open with a Fedora 'version' of '29'. Package Maintainer: If you wish for this bug to remain open because you plan to fix it in a currently maintained version, simply change the 'version' to a later Fedora version. Thank you for reporting this issue and we are sorry that we were not able to fix it before Fedora 29 is end of life. If you would still like to see this bug fixed and are able to reproduce it against a later version of Fedora, you are encouraged change the 'version' to a later Fedora version prior this bug is closed as described in the policy above. Although we aim to fix as many bugs as possible during every release's lifetime, sometimes those efforts are overtaken by events. Often a more recent Fedora release includes newer upstream software that fixes bugs or makes them obsolete.
Fedora 29 changed to end-of-life (EOL) status on 2019-11-26. Fedora 29 is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of Fedora please feel free to reopen this bug against that version. If you are unable to reopen this bug, please file a new report against the current release. If you experience problems, please add a comment to this bug. Thank you for reporting this bug and we are sorry it could not be fixed.