Bug 1834234 - the nfsdcld service is not confined by SELinux
Summary: the nfsdcld service is not confined by SELinux
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 32
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Richard Fiľo
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-05-11 11:04 UTC by Milos Malik
Modified: 2020-09-03 12:32 UTC (History)
7 users (show)

Fixed In Version: selinux-policy-3.14.5-43.fc32
Clone Of:
: 2026588 (view as bug list)
Environment:
Last Closed: 2020-08-31 15:50:00 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Milos Malik 2020-05-11 11:04:33 UTC
Description of problem:
 * the NFSv4 Client Tracking Daemon runs as unconfined_service_t

# ls -Z /usr/sbin/nfsdcld
system_u:object_r:bin_t:s0 /usr/sbin/nfsdcld
# matchpathcon /usr/sbin/nfsdcld
/usr/sbin/nfsdcld	system_u:object_r:bin_t:s0
#

Version-Release number of selected component (if applicable):
nfs-utils-2.4.3-1.rc2.fc32.x86_64
selinux-policy-3.14.5-38.fc32.noarch
selinux-policy-devel-3.14.5-38.fc32.noarch
selinux-policy-doc-3.14.5-38.fc32.noarch
selinux-policy-targeted-3.14.5-38.fc32.noarch

How reproducible:
 * always

Steps to Reproduce:
1. get a Fedora 31 or 32 machine (targeted policy is active)
2. start the nfsdcld service
3. ps -efZ | grep nfsdcld

Actual results:
system_u:system_r:unconfined_service_t:s0 root 713     1  0 11:52 ?        00:00:00 /usr/sbin/nfsdcld

Expected results:
 * the nfsdcld runs confined by SELinux

Comment 1 Milos Malik 2020-05-11 13:04:52 UTC
If the /usr/sbin/nfsdcld file is labeled nfsd_exec_t then the service does not start and following SELinux denial appears:

----
type=PROCTITLE msg=audit(05/11/2020 14:59:37.182:1455) : proctitle=/usr/sbin/nfsdcld 
type=SYSCALL msg=audit(05/11/2020 14:59:37.182:1455) : arch=x86_64 syscall=prctl success=no exit=EPERM(Operation not permitted) a0=PR_CAPBSET_DROP a1=chown a2=0x0 a3=0x0 items=0 ppid=1 pid=34260 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=nfsdcld exe=/usr/sbin/nfsdcld subj=system_u:system_r:nfsd_t:s0 key=(null) 
type=AVC msg=audit(05/11/2020 14:59:37.182:1455) : avc:  denied  { setpcap } for  pid=34260 comm=nfsdcld capability=setpcap  scontext=system_u:system_r:nfsd_t:s0 tcontext=system_u:system_r:nfsd_t:s0 tclass=capability permissive=0 
----

If the /usr/sbin/nfsdcld file is labeled rpcd_exec_t then there are no SELinux denials and the service starts successfully:

# service nfsdcld status
Redirecting to /bin/systemctl status nfsdcld.service
● nfsdcld.service - NFSv4 Client Tracking Daemon
     Loaded: loaded (/usr/lib/systemd/system/nfsdcld.service; static; vendor preset: disabled)
     Active: active (running) since Mon 2020-05-11 14:59:55 CEST; 2min 12s ago
    Process: 34310 ExecStart=/usr/sbin/nfsdcld (code=exited, status=0/SUCCESS)
   Main PID: 34311 (nfsdcld)
      Tasks: 1 (limit: 2330)
     Memory: 932.0K
        CPU: 3ms
     CGroup: /system.slice/nfsdcld.service
             └─34311 /usr/sbin/nfsdcld

May 11 14:59:55 localhost.localdomain systemd[1]: Starting NFSv4 Client Tracking Daemon...
May 11 14:59:55 localhost.localdomain systemd[1]: Started NFSv4 Client Tracking Daemon.
# ps -efZ | grep nfsdcld
system_u:system_r:rpcd_t:s0     root       34311       1  0 14:59 ?        00:00:00 /usr/sbin/nfsdcld
#

Comment 4 Richard Fiľo 2020-08-19 10:40:58 UTC
If the /usr/sbin/nfsdcld file is labeled rpcd_exec_t then there is still a AVC there:

avc:  denied  { read } for  pid=20465 comm="nfsdcld" name="nfsv4recoverydir" dev="nfsd" ino=18 scontext=system_u:system_r:rpcd_t:s0 tcontext=system_u:object_r:nfsd_fs_t:s0 tclass=file permissive=0

Comment 6 Lukas Vrabec 2020-08-19 11:15:52 UTC
commit 07c22d0d3a2f2c4e7a4d11da285e7eb3167a33e2 (HEAD -> f32, origin/f32)
Author: Richard Filo <rfilo>
Date:   Mon Aug 10 09:19:56 2020 +0200

    The nfsdcld service is now confined by SELinux
    
    The nfsdcld service is confined by rpcd_t domain.
    Allow rpcd_t domain to read files on an nfsd filesystem.
    
    fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1834234

Comment 7 Fedora Update System 2020-08-27 21:10:35 UTC
FEDORA-2020-740de661da has been submitted as an update to Fedora 32. https://bodhi.fedoraproject.org/updates/FEDORA-2020-740de661da

Comment 9 Fedora Update System 2020-08-28 14:55:07 UTC
FEDORA-2020-740de661da has been pushed to the Fedora 32 testing repository.
In short time you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2020-740de661da`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2020-740de661da

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 10 Fedora Update System 2020-08-31 15:50:00 UTC
FEDORA-2020-740de661da has been pushed to the Fedora 32 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.