Bug 1897388 - SELinux is preventing dhclient-script from read access on the file /usr/bin/chronyc
Summary: SELinux is preventing dhclient-script from read access on the file /usr/bin/c...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 33
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 1921273 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-11-12 22:39 UTC by Todd
Modified: 2022-06-11 07:41 UTC (History)
9 users (show)

Fixed In Version: selinux-policy-3.14.6-37.fc33
Clone Of:
Environment:
Last Closed: 2021-05-09 01:15:05 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Todd 2020-11-12 22:39:37 UTC
Fedora 33, x64
$ rpm -qa selinux\*
selinux-policy-targeted-3.14.6-29.fc33.noarch
selinux-policy-devel-3.14.6-29.fc33.noarch
selinux-policy-3.14.6-29.fc33.noarch

I keep getting this error and the recommended fix is ignored.  So as recommended from the error message, I am reporting it as a bug.



SELinux is preventing dhclient-script from read access on the file /usr/bin/chronyc.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that dhclient-script should be allowed read access on the chronyc file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'dhclient-script' --raw | audit2allow -M my-dhclientscript
# semodule -X 300 -i my-dhclientscript.pp

Additional Information:
Source Context                unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023
Target Context                system_u:object_r:chronyc_exec_t:s0
Target Objects                /usr/bin/chronyc [ file ]
Source                        dhclient-script
Source Path                   dhclient-script
Port                          <Unknown>
Host                          rn6.rent-a-nerd.local
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            <Unknown>
Local Policy RPM              selinux-policy-targeted-3.14.6-29.fc33.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     rn6.rent-a-nerd.local
Platform                      Linux rn6.rent-a-nerd.local 5.8.18-300.fc33.x86_64
                              #1 SMP Mon Nov 2 19:09:05 UTC 2020 x86_64 x86_64
Alert Count                   12
First Seen                    2020-11-08 20:23:06 PST
Last Seen                     2020-11-12 13:40:42 PST
Local ID                      c22bc359-efcb-40e5-8c68-b207696f3af9

Raw Audit Messages
type=AVC msg=audit(1605217242.16:3720): avc:  denied  { read } for  pid=19946 comm="dhclient-script" name="chronyc" dev="dm-1" ino=19162229 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0


Hash: dhclient-script,dhcpc_t,chronyc_exec_t,file,read

Comment 1 Milos Malik 2020-11-23 20:37:22 UTC
Following SELinux denials appeared on my Fedora 33 VM:
----
type=PROCTITLE msg=audit(11/23/2020 20:13:10.366:460) : proctitle=/usr/bin/bash /usr/sbin/dhclient-script 
type=PATH msg=audit(11/23/2020 20:13:10.366:460) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/23/2020 20:13:10.366:460) : cwd=/etc/sysconfig/network-scripts 
type=SYSCALL msg=audit(11/23/2020 20:13:10.366:460) : arch=x86_64 syscall=execve success=no exit=EACCES(Permission denied) a0=0x556d2fa65530 a1=0x556d2fa693d0 a2=0x556d2fa479e0 a3=0x1b6 items=1 ppid=5763 pid=5800 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=tty1 ses=1 comm=dhclient-script exe=/usr/bin/bash subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/23/2020 20:13:10.366:460) : avc:  denied  { execute } for  pid=5800 comm=dhclient-script name=chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 
----
type=PROCTITLE msg=audit(11/23/2020 20:13:10.367:461) : proctitle=/usr/bin/bash /usr/sbin/dhclient-script 
type=PATH msg=audit(11/23/2020 20:13:10.367:461) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/23/2020 20:13:10.367:461) : cwd=/etc/sysconfig/network-scripts 
type=SYSCALL msg=audit(11/23/2020 20:13:10.367:461) : arch=x86_64 syscall=stat success=no exit=EACCES(Permission denied) a0=0x556d2fa65530 a1=0x7ffebc21e930 a2=0x7ffebc21e930 a3=0x1b6 items=1 ppid=5763 pid=5800 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=tty1 ses=1 comm=dhclient-script exe=/usr/bin/bash subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/23/2020 20:13:10.367:461) : avc:  denied  { getattr } for  pid=5800 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 
----

Comment 2 Milos Malik 2020-11-24 07:54:34 UTC
Steps to Reproduce:

1) log in as root
2) run: dhclient

Comment 3 Milos Malik 2020-11-24 07:59:24 UTC
Here are SELinux denials which appeared in permissive mode:
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.271:401) : proctitle=/usr/bin/chronyc reload sources 
type=PATH msg=audit(11/24/2020 08:55:04.271:401) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=5621 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=PATH msg=audit(11/24/2020 08:55:04.271:401) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.271:401) : cwd=/etc/sysconfig/network-scripts 
type=EXECVE msg=audit(11/24/2020 08:55:04.271:401) : argc=3 a0=/usr/bin/chronyc a1=reload a2=sources 
type=SYSCALL msg=audit(11/24/2020 08:55:04.271:401) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x559faed36dc0 a1=0x559faed35ed0 a2=0x559faed189e0 a3=0x1b6 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc:  denied  { map } for  pid=4713 comm=chronyc path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc:  denied  { execute_no_trans } for  pid=4713 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc:  denied  { read open } for  pid=4713 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc:  denied  { execute } for  pid=4713 comm=dhclient-script name=chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.273:402) : proctitle=/usr/bin/chronyc reload sources 
type=PATH msg=audit(11/24/2020 08:55:04.273:402) : item=1 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=CREATE cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=PATH msg=audit(11/24/2020 08:55:04.273:402) : item=0 name=/run/chrony/ inode=64416 dev=00:19 mode=dir,750 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=PARENT cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.273:402) : cwd=/etc/sysconfig/network-scripts 
type=SOCKADDR msg=audit(11/24/2020 08:55:04.273:402) : saddr={ saddr_fam=local path=/run/chrony/chronyc.4713.sock } 
type=SYSCALL msg=audit(11/24/2020 08:55:04.273:402) : arch=x86_64 syscall=bind success=yes exit=0 a0=0x3 a1=0x7ffedc5d1290 a2=0x6e a3=0x7f354e683fc0 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc:  denied  { create } for  pid=4713 comm=chronyc name=chronyc.4713.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc:  denied  { add_name } for  pid=4713 comm=chronyc name=chronyc.4713.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc:  denied  { write } for  pid=4713 comm=chronyc name=chrony dev="tmpfs" ino=64416 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc:  denied  { dac_override } for  pid=4713 comm=chronyc capability=dac_override  scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=capability permissive=1 
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.273:403) : proctitle=/usr/bin/chronyc reload sources 
type=PATH msg=audit(11/24/2020 08:55:04.273:403) : item=0 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.273:403) : cwd=/etc/sysconfig/network-scripts 
type=SYSCALL msg=audit(11/24/2020 08:55:04.273:403) : arch=x86_64 syscall=chmod success=yes exit=0 a0=0x55c021043fb0 a1=0666 a2=0x6e a3=0x7f354e683fc0 items=1 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.273:403) : avc:  denied  { setattr } for  pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.274:404) : proctitle=/usr/bin/chronyc reload sources 
type=PATH msg=audit(11/24/2020 08:55:04.274:404) : item=0 name=/run/chrony/chronyd.sock inode=65003 dev=00:19 mode=socket,755 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.274:404) : cwd=/etc/sysconfig/network-scripts 
type=SOCKADDR msg=audit(11/24/2020 08:55:04.274:404) : saddr={ saddr_fam=local path=/run/chrony/chronyd.sock } 
type=SYSCALL msg=audit(11/24/2020 08:55:04.274:404) : arch=x86_64 syscall=connect success=yes exit=0 a0=0x3 a1=0x7ffedc5d1290 a2=0x6e a3=0x7f354e683fc0 items=1 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.274:404) : avc:  denied  { sendto } for  pid=4713 comm=chronyc path=/run/chrony/chronyd.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:system_r:chronyd_t:s0 tclass=unix_dgram_socket permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.274:404) : avc:  denied  { write } for  pid=4713 comm=chronyc name=chronyd.sock dev="tmpfs" ino=65003 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.275:405) : proctitle=/usr/sbin/chronyd 
type=PATH msg=audit(11/24/2020 08:55:04.275:405) : item=0 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,666 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.275:405) : cwd=/ 
type=SOCKADDR msg=audit(11/24/2020 08:55:04.275:405) : saddr={ saddr_fam=local path=/run/chrony/chronyc.4713.sock } 
type=SYSCALL msg=audit(11/24/2020 08:55:04.275:405) : arch=x86_64 syscall=sendmsg success=yes exit=28 a0=0x8 a1=0x7fff7aa834c0 a2=0x0 a3=0x7f451920ffc0 items=1 ppid=1 pid=727 auid=unset uid=chrony gid=chrony euid=chrony suid=chrony fsuid=chrony egid=chrony sgid=chrony fsgid=chrony tty=(none) ses=unset comm=chronyd exe=/usr/sbin/chronyd subj=system_u:system_r:chronyd_t:s0 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.275:405) : avc:  denied  { sendto } for  pid=727 comm=chronyd path=/run/chrony/chronyc.4713.sock scontext=system_u:system_r:chronyd_t:s0 tcontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=unix_dgram_socket permissive=1 
----
type=PROCTITLE msg=audit(11/24/2020 08:55:04.275:406) : proctitle=/usr/bin/chronyc reload sources 
type=PATH msg=audit(11/24/2020 08:55:04.275:406) : item=1 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,666 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=DELETE cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=PATH msg=audit(11/24/2020 08:55:04.275:406) : item=0 name=/run/chrony/ inode=64416 dev=00:19 mode=dir,750 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=PARENT cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(11/24/2020 08:55:04.275:406) : cwd=/etc/sysconfig/network-scripts 
type=SYSCALL msg=audit(11/24/2020 08:55:04.275:406) : arch=x86_64 syscall=unlink success=yes exit=0 a0=0x7ffedc5d12c2 a1=0x7ffedc5d12c0 a2=0x7ffedc5d12bc a3=0x70 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) 
type=AVC msg=audit(11/24/2020 08:55:04.275:406) : avc:  denied  { unlink } for  pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 
type=AVC msg=audit(11/24/2020 08:55:04.275:406) : avc:  denied  { remove_name } for  pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 
----

Because SELinux policy does not define any transition from dhcpc_t to chronyc_t:

# sesearch -s dhcpc_t -t chronyc_exec_t -T
# 

the chronyc process runs under dhcpc_t context.

Comment 4 Milos Malik 2020-11-24 11:19:48 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/136

The PR waits for review.

Comment 5 Patrick Ladd 2021-01-19 01:36:15 UTC
Policy changes to clear denials on my system so far:

module my-dhclientscript 1.0;

require {
type dhcpc_t;
type chronyc_exec_t;
class capability dac_override;
class file { execute execute_no_trans getattr open read };
}

#============= dhcpc_t ==============

allow dhcpc_t chronyc_exec_t:file { execute execute_no_trans getattr open read };

allow dhcpc_t self:capability dac_override;

Comment 6 Patrick Ladd 2021-01-19 22:48:57 UTC
Also had to add policies for chronyc & chronyd:

module my-chronyc 1.0;

require {
type chronyd_t;
type chronyc_exec_t;
type dhcpc_t;
type chronyd_var_run_t;
class file map;
class dir { add_name remove_name write };
class sock_file { create setattr unlink };
class unix_dgram_socket sendto;
}

#============= dhcpc_t ==============

#!!!! This avc is allowed in the current policy
allow dhcpc_t chronyc_exec_t:file map;
allow dhcpc_t chronyd_t:unix_dgram_socket sendto;

#!!!! This avc is allowed in the current policy
allow dhcpc_t chronyd_var_run_t:dir { add_name remove_name write };
allow dhcpc_t chronyd_var_run_t:sock_file unlink;

#!!!! This avc is allowed in the current policy
allow dhcpc_t chronyd_var_run_t:sock_file { create setattr };

module my-chronyd 1.0;

require {
type chronyd_t;
type dhcpc_t;
class unix_dgram_socket sendto;
}

#============= chronyd_t ==============
allow chronyd_t dhcpc_t:unix_dgram_socket sendto;

Comment 7 Zdenek Pytela 2021-01-28 10:43:58 UTC
*** Bug 1921273 has been marked as a duplicate of this bug. ***

Comment 8 Zdenek Pytela 2021-04-01 16:21:35 UTC
I've submitted a Fedora PR to address the issue:
https://github.com/fedora-selinux/selinux-policy/pull/672

Comment 9 Zdenek Pytela 2021-04-01 19:47:27 UTC
Backported to f33:
commit 32aa3f5509900563632fec1a1536c84da50553ed (HEAD -> f33, upstream/f33, origin/f33)
Author: Zdenek Pytela <zpytela>
Date:   Thu Apr 1 17:36:08 2021 +0200

    Allow dhcpc_t domain transition to chronyc_t

    This permission is required when dhclient-script executes
    the chrony.sh script from /etc/dhcp/dhclient.d.

    Resolves: rhbz#1897388

Comment 10 Todd 2021-04-02 00:18:51 UTC
Do you have a time frame on when we will see this in the F33 repo?

Comment 11 Zdenek Pytela 2021-04-06 09:30:49 UTC
(In reply to Todd from comment #10)
> Do you have a time frame on when we will see this in the F33 repo?

I am sorry, there are currently no estimations other than during April.

Comment 12 Fedora Update System 2021-04-28 11:33:56 UTC
FEDORA-2021-050d4e8def has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def

Comment 13 Fedora Update System 2021-04-29 01:45:41 UTC
FEDORA-2021-050d4e8def has been pushed to the Fedora 33 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-050d4e8def`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 14 Todd 2021-04-29 01:58:08 UTC
(In reply to Fedora Update System from comment #13)
> FEDORA-2021-050d4e8def has been pushed to the Fedora 33 testing repository.
> Soon you'll be able to install the update with the following command:
> `sudo dnf upgrade --enablerepo=updates-testing
> --advisory=FEDORA-2021-050d4e8def`
> You can provide feedback for this update here:
> https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def
> 
> See also https://fedoraproject.org/wiki/QA:Updates_Testing for more
> information on how to test updates.

Unfortunately, it does not work:


SELinux is preventing dhclient-script from read access on the file /usr/bin/chronyc.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that dhclient-script should be allowed read access on the chronyc file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'dhclient-script' --raw | audit2allow -M my-dhclientscript
# semodule -X 300 -i my-dhclientscript.pp

Additional Information:
Source Context                unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023
Target Context                system_u:object_r:chronyc_exec_t:s0
Target Objects                /usr/bin/chronyc [ file ]
Source                        dhclient-script
Source Path                   dhclient-script
Port                          <Unknown>
Host                          rn6.rent-a-nerd.local
Source RPM Packages           
Target RPM Packages           chrony-4.0-1.fc33.x86_64
SELinux Policy RPM            selinux-policy-targeted-3.14.6-36.fc33.noarch
Local Policy RPM              selinux-policy-targeted-3.14.6-36.fc33.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     rn6.rent-a-nerd.local
Platform                      Linux rn6.rent-a-nerd.local
                              5.11.15-200.fc33.x86_64 #1 SMP Fri Apr 16 13:41:20
                              UTC 2021 x86_64 x86_64
Alert Count                   3
First Seen                    2021-04-28 18:54:42 PDT
Last Seen                     2021-04-28 18:54:42 PDT
Local ID                      4e589b12-574e-4869-9da2-0173fd2a2a8d

Raw Audit Messages
type=AVC msg=audit(1619661282.228:1495): avc:  denied  { read } for  pid=34945 comm="dhclient-script" name="chronyc" dev="dm-1" ino=19162229 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0


Hash: dhclient-script,dhcpc_t,chronyc_exec_t,file,read



# semodule -X 300 -i my-dhclientscript.pp
libsemanage.map_file: Unable to open my-dhclientscript.pp
 (No such file or directory).
libsemanage.semanage_direct_install_file: Unable to read file my-dhclientscript.pp
 (No such file or directory).
semodule:  Failed on my-dhclientscript.pp!

Comment 15 Fedora Update System 2021-05-09 01:15:05 UTC
FEDORA-2021-050d4e8def has been pushed to the Fedora 33 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 16 Todd 2021-05-10 23:31:09 UTC
Fedora 34 have the same problem.  Will we be seeing this fix in Fedora 34 any time soon?

Comment 17 Zdenek Pytela 2021-05-20 12:42:48 UTC
This particular bug has been fixed in F33, F34, and rawhide. If you see any other denial, please file a new bz.


Note You need to log in before you can comment on or make changes to this bug.