Fedora Account System
Red Hat Associate
Red Hat Customer
Fedora 33, x64 $ rpm -qa selinux\* selinux-policy-targeted-3.14.6-29.fc33.noarch selinux-policy-devel-3.14.6-29.fc33.noarch selinux-policy-3.14.6-29.fc33.noarch I keep getting this error and the recommended fix is ignored. So as recommended from the error message, I am reporting it as a bug. SELinux is preventing dhclient-script from read access on the file /usr/bin/chronyc. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that dhclient-script should be allowed read access on the chronyc file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'dhclient-script' --raw | audit2allow -M my-dhclientscript # semodule -X 300 -i my-dhclientscript.pp Additional Information: Source Context unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 Target Context system_u:object_r:chronyc_exec_t:s0 Target Objects /usr/bin/chronyc [ file ] Source dhclient-script Source Path dhclient-script Port <Unknown> Host rn6.rent-a-nerd.local Source RPM Packages Target RPM Packages SELinux Policy RPM <Unknown> Local Policy RPM selinux-policy-targeted-3.14.6-29.fc33.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name rn6.rent-a-nerd.local Platform Linux rn6.rent-a-nerd.local 5.8.18-300.fc33.x86_64 #1 SMP Mon Nov 2 19:09:05 UTC 2020 x86_64 x86_64 Alert Count 12 First Seen 2020-11-08 20:23:06 PST Last Seen 2020-11-12 13:40:42 PST Local ID c22bc359-efcb-40e5-8c68-b207696f3af9 Raw Audit Messages type=AVC msg=audit(1605217242.16:3720): avc: denied { read } for pid=19946 comm="dhclient-script" name="chronyc" dev="dm-1" ino=19162229 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 Hash: dhclient-script,dhcpc_t,chronyc_exec_t,file,read
Following SELinux denials appeared on my Fedora 33 VM: ---- type=PROCTITLE msg=audit(11/23/2020 20:13:10.366:460) : proctitle=/usr/bin/bash /usr/sbin/dhclient-script type=PATH msg=audit(11/23/2020 20:13:10.366:460) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/23/2020 20:13:10.366:460) : cwd=/etc/sysconfig/network-scripts type=SYSCALL msg=audit(11/23/2020 20:13:10.366:460) : arch=x86_64 syscall=execve success=no exit=EACCES(Permission denied) a0=0x556d2fa65530 a1=0x556d2fa693d0 a2=0x556d2fa479e0 a3=0x1b6 items=1 ppid=5763 pid=5800 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=tty1 ses=1 comm=dhclient-script exe=/usr/bin/bash subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/23/2020 20:13:10.366:460) : avc: denied { execute } for pid=5800 comm=dhclient-script name=chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 ---- type=PROCTITLE msg=audit(11/23/2020 20:13:10.367:461) : proctitle=/usr/bin/bash /usr/sbin/dhclient-script type=PATH msg=audit(11/23/2020 20:13:10.367:461) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/23/2020 20:13:10.367:461) : cwd=/etc/sysconfig/network-scripts type=SYSCALL msg=audit(11/23/2020 20:13:10.367:461) : arch=x86_64 syscall=stat success=no exit=EACCES(Permission denied) a0=0x556d2fa65530 a1=0x7ffebc21e930 a2=0x7ffebc21e930 a3=0x1b6 items=1 ppid=5763 pid=5800 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=tty1 ses=1 comm=dhclient-script exe=/usr/bin/bash subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/23/2020 20:13:10.367:461) : avc: denied { getattr } for pid=5800 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 ----
Steps to Reproduce: 1) log in as root 2) run: dhclient
Here are SELinux denials which appeared in permissive mode: ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.271:401) : proctitle=/usr/bin/chronyc reload sources type=PATH msg=audit(11/24/2020 08:55:04.271:401) : item=1 name=/lib64/ld-linux-x86-64.so.2 inode=5621 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:ld_so_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=PATH msg=audit(11/24/2020 08:55:04.271:401) : item=0 name=/usr/bin/chronyc inode=7391 dev=fc:02 mode=file,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:chronyc_exec_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.271:401) : cwd=/etc/sysconfig/network-scripts type=EXECVE msg=audit(11/24/2020 08:55:04.271:401) : argc=3 a0=/usr/bin/chronyc a1=reload a2=sources type=SYSCALL msg=audit(11/24/2020 08:55:04.271:401) : arch=x86_64 syscall=execve success=yes exit=0 a0=0x559faed36dc0 a1=0x559faed35ed0 a2=0x559faed189e0 a3=0x1b6 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc: denied { map } for pid=4713 comm=chronyc path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc: denied { execute_no_trans } for pid=4713 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc: denied { read open } for pid=4713 comm=dhclient-script path=/usr/bin/chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.271:401) : avc: denied { execute } for pid=4713 comm=dhclient-script name=chronyc dev="vda2" ino=7391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.273:402) : proctitle=/usr/bin/chronyc reload sources type=PATH msg=audit(11/24/2020 08:55:04.273:402) : item=1 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=CREATE cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=PATH msg=audit(11/24/2020 08:55:04.273:402) : item=0 name=/run/chrony/ inode=64416 dev=00:19 mode=dir,750 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=PARENT cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.273:402) : cwd=/etc/sysconfig/network-scripts type=SOCKADDR msg=audit(11/24/2020 08:55:04.273:402) : saddr={ saddr_fam=local path=/run/chrony/chronyc.4713.sock } type=SYSCALL msg=audit(11/24/2020 08:55:04.273:402) : arch=x86_64 syscall=bind success=yes exit=0 a0=0x3 a1=0x7ffedc5d1290 a2=0x6e a3=0x7f354e683fc0 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc: denied { create } for pid=4713 comm=chronyc name=chronyc.4713.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc: denied { add_name } for pid=4713 comm=chronyc name=chronyc.4713.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc: denied { write } for pid=4713 comm=chronyc name=chrony dev="tmpfs" ino=64416 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.273:402) : avc: denied { dac_override } for pid=4713 comm=chronyc capability=dac_override scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=capability permissive=1 ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.273:403) : proctitle=/usr/bin/chronyc reload sources type=PATH msg=audit(11/24/2020 08:55:04.273:403) : item=0 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.273:403) : cwd=/etc/sysconfig/network-scripts type=SYSCALL msg=audit(11/24/2020 08:55:04.273:403) : arch=x86_64 syscall=chmod success=yes exit=0 a0=0x55c021043fb0 a1=0666 a2=0x6e a3=0x7f354e683fc0 items=1 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.273:403) : avc: denied { setattr } for pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.274:404) : proctitle=/usr/bin/chronyc reload sources type=PATH msg=audit(11/24/2020 08:55:04.274:404) : item=0 name=/run/chrony/chronyd.sock inode=65003 dev=00:19 mode=socket,755 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.274:404) : cwd=/etc/sysconfig/network-scripts type=SOCKADDR msg=audit(11/24/2020 08:55:04.274:404) : saddr={ saddr_fam=local path=/run/chrony/chronyd.sock } type=SYSCALL msg=audit(11/24/2020 08:55:04.274:404) : arch=x86_64 syscall=connect success=yes exit=0 a0=0x3 a1=0x7ffedc5d1290 a2=0x6e a3=0x7f354e683fc0 items=1 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.274:404) : avc: denied { sendto } for pid=4713 comm=chronyc path=/run/chrony/chronyd.sock scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:system_r:chronyd_t:s0 tclass=unix_dgram_socket permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.274:404) : avc: denied { write } for pid=4713 comm=chronyc name=chronyd.sock dev="tmpfs" ino=65003 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.275:405) : proctitle=/usr/sbin/chronyd type=PATH msg=audit(11/24/2020 08:55:04.275:405) : item=0 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,666 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.275:405) : cwd=/ type=SOCKADDR msg=audit(11/24/2020 08:55:04.275:405) : saddr={ saddr_fam=local path=/run/chrony/chronyc.4713.sock } type=SYSCALL msg=audit(11/24/2020 08:55:04.275:405) : arch=x86_64 syscall=sendmsg success=yes exit=28 a0=0x8 a1=0x7fff7aa834c0 a2=0x0 a3=0x7f451920ffc0 items=1 ppid=1 pid=727 auid=unset uid=chrony gid=chrony euid=chrony suid=chrony fsuid=chrony egid=chrony sgid=chrony fsgid=chrony tty=(none) ses=unset comm=chronyd exe=/usr/sbin/chronyd subj=system_u:system_r:chronyd_t:s0 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.275:405) : avc: denied { sendto } for pid=727 comm=chronyd path=/run/chrony/chronyc.4713.sock scontext=system_u:system_r:chronyd_t:s0 tcontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tclass=unix_dgram_socket permissive=1 ---- type=PROCTITLE msg=audit(11/24/2020 08:55:04.275:406) : proctitle=/usr/bin/chronyc reload sources type=PATH msg=audit(11/24/2020 08:55:04.275:406) : item=1 name=/run/chrony/chronyc.4713.sock inode=178391 dev=00:19 mode=socket,666 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:chronyd_var_run_t:s0 nametype=DELETE cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=PATH msg=audit(11/24/2020 08:55:04.275:406) : item=0 name=/run/chrony/ inode=64416 dev=00:19 mode=dir,750 ouid=chrony ogid=chrony rdev=00:00 obj=system_u:object_r:chronyd_var_run_t:s0 nametype=PARENT cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(11/24/2020 08:55:04.275:406) : cwd=/etc/sysconfig/network-scripts type=SYSCALL msg=audit(11/24/2020 08:55:04.275:406) : arch=x86_64 syscall=unlink success=yes exit=0 a0=0x7ffedc5d12c2 a1=0x7ffedc5d12c0 a2=0x7ffedc5d12bc a3=0x70 items=2 ppid=4676 pid=4713 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=pts0 ses=3 comm=chronyc exe=/usr/bin/chronyc subj=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(11/24/2020 08:55:04.275:406) : avc: denied { unlink } for pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:chronyd_var_run_t:s0 tclass=sock_file permissive=1 type=AVC msg=audit(11/24/2020 08:55:04.275:406) : avc: denied { remove_name } for pid=4713 comm=chronyc name=chronyc.4713.sock dev="tmpfs" ino=178391 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyd_var_run_t:s0 tclass=dir permissive=1 ---- Because SELinux policy does not define any transition from dhcpc_t to chronyc_t: # sesearch -s dhcpc_t -t chronyc_exec_t -T # the chronyc process runs under dhcpc_t context.
Test coverage for this bug exists in a form of PR: * https://src.fedoraproject.org/tests/selinux/pull-request/136 The PR waits for review.
Policy changes to clear denials on my system so far: module my-dhclientscript 1.0; require { type dhcpc_t; type chronyc_exec_t; class capability dac_override; class file { execute execute_no_trans getattr open read }; } #============= dhcpc_t ============== allow dhcpc_t chronyc_exec_t:file { execute execute_no_trans getattr open read }; allow dhcpc_t self:capability dac_override;
Also had to add policies for chronyc & chronyd: module my-chronyc 1.0; require { type chronyd_t; type chronyc_exec_t; type dhcpc_t; type chronyd_var_run_t; class file map; class dir { add_name remove_name write }; class sock_file { create setattr unlink }; class unix_dgram_socket sendto; } #============= dhcpc_t ============== #!!!! This avc is allowed in the current policy allow dhcpc_t chronyc_exec_t:file map; allow dhcpc_t chronyd_t:unix_dgram_socket sendto; #!!!! This avc is allowed in the current policy allow dhcpc_t chronyd_var_run_t:dir { add_name remove_name write }; allow dhcpc_t chronyd_var_run_t:sock_file unlink; #!!!! This avc is allowed in the current policy allow dhcpc_t chronyd_var_run_t:sock_file { create setattr }; module my-chronyd 1.0; require { type chronyd_t; type dhcpc_t; class unix_dgram_socket sendto; } #============= chronyd_t ============== allow chronyd_t dhcpc_t:unix_dgram_socket sendto;
*** Bug 1921273 has been marked as a duplicate of this bug. ***
I've submitted a Fedora PR to address the issue: https://github.com/fedora-selinux/selinux-policy/pull/672
Backported to f33: commit 32aa3f5509900563632fec1a1536c84da50553ed (HEAD -> f33, upstream/f33, origin/f33) Author: Zdenek Pytela <zpytela> Date: Thu Apr 1 17:36:08 2021 +0200 Allow dhcpc_t domain transition to chronyc_t This permission is required when dhclient-script executes the chrony.sh script from /etc/dhcp/dhclient.d. Resolves: rhbz#1897388
Do you have a time frame on when we will see this in the F33 repo?
(In reply to Todd from comment #10) > Do you have a time frame on when we will see this in the F33 repo? I am sorry, there are currently no estimations other than during April.
FEDORA-2021-050d4e8def has been submitted as an update to Fedora 33. https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def
FEDORA-2021-050d4e8def has been pushed to the Fedora 33 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2021-050d4e8def` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
(In reply to Fedora Update System from comment #13) > FEDORA-2021-050d4e8def has been pushed to the Fedora 33 testing repository. > Soon you'll be able to install the update with the following command: > `sudo dnf upgrade --enablerepo=updates-testing > --advisory=FEDORA-2021-050d4e8def` > You can provide feedback for this update here: > https://bodhi.fedoraproject.org/updates/FEDORA-2021-050d4e8def > > See also https://fedoraproject.org/wiki/QA:Updates_Testing for more > information on how to test updates. Unfortunately, it does not work: SELinux is preventing dhclient-script from read access on the file /usr/bin/chronyc. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that dhclient-script should be allowed read access on the chronyc file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'dhclient-script' --raw | audit2allow -M my-dhclientscript # semodule -X 300 -i my-dhclientscript.pp Additional Information: Source Context unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 Target Context system_u:object_r:chronyc_exec_t:s0 Target Objects /usr/bin/chronyc [ file ] Source dhclient-script Source Path dhclient-script Port <Unknown> Host rn6.rent-a-nerd.local Source RPM Packages Target RPM Packages chrony-4.0-1.fc33.x86_64 SELinux Policy RPM selinux-policy-targeted-3.14.6-36.fc33.noarch Local Policy RPM selinux-policy-targeted-3.14.6-36.fc33.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name rn6.rent-a-nerd.local Platform Linux rn6.rent-a-nerd.local 5.11.15-200.fc33.x86_64 #1 SMP Fri Apr 16 13:41:20 UTC 2021 x86_64 x86_64 Alert Count 3 First Seen 2021-04-28 18:54:42 PDT Last Seen 2021-04-28 18:54:42 PDT Local ID 4e589b12-574e-4869-9da2-0173fd2a2a8d Raw Audit Messages type=AVC msg=audit(1619661282.228:1495): avc: denied { read } for pid=34945 comm="dhclient-script" name="chronyc" dev="dm-1" ino=19162229 scontext=unconfined_u:system_r:dhcpc_t:s0-s0:c0.c1023 tcontext=system_u:object_r:chronyc_exec_t:s0 tclass=file permissive=0 Hash: dhclient-script,dhcpc_t,chronyc_exec_t,file,read # semodule -X 300 -i my-dhclientscript.pp libsemanage.map_file: Unable to open my-dhclientscript.pp (No such file or directory). libsemanage.semanage_direct_install_file: Unable to read file my-dhclientscript.pp (No such file or directory). semodule: Failed on my-dhclientscript.pp!
FEDORA-2021-050d4e8def has been pushed to the Fedora 33 stable repository. If problem still persists, please make note of it in this bug report.
Fedora 34 have the same problem. Will we be seeing this fix in Fedora 34 any time soon?
This particular bug has been fixed in F33, F34, and rawhide. If you see any other denial, please file a new bz.