Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing rpmdb from 'write' accesses on the sock_file /var/lib/sss/pipes/nss. ***** Plugin catchall (100. confidence) suggests ************************** Se ci credi rpmdb dovrebbe essere consentito write accesso al nss sock_file per impostazione predefinita. Then si dovrebbe riportare il problema come bug. E' possibile generare un modulo di politica locale per consentire questo accesso. Do consentire questo accesso per ora eseguendo: # ausearch -c 'rpmdb'--raw | audit2allow -M my-$MODULE_NOME # semodule -X 300 -i miei-rpmdb.pp Additional Information: Source Context unconfined_u:unconfined_r:rpmdb_t:s0-s0:c0.c1023 Target Context system_u:object_r:sssd_var_lib_t:s0 Target Objects /var/lib/sss/pipes/nss [ sock_file ] Source rpmdb Source Path rpmdb Port <Sconosciuto> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-3.14.6-30.fc33.noarch Local Policy RPM selinux-policy-targeted-3.14.6-30.fc33.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 5.9.8-200.fc33.x86_64 #1 SMP Tue Nov 10 21:58:19 UTC 2020 x86_64 x86_64 Alert Count 1 First Seen 2020-11-22 18:11:39 CET Last Seen 2020-11-22 18:11:39 CET Local ID 33294c71-0bb4-491c-bdd2-96e4acaf0237 Raw Audit Messages type=AVC msg=audit(1606065099.545:904): avc: denied { write } for pid=17254 comm="rpmdb" name="nss" dev="dm-0" ino=4325420 scontext=unconfined_u:unconfined_r:rpmdb_t:s0-s0:c0.c1023 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=sock_file permissive=1 Hash: rpmdb,rpmdb_t,sssd_var_lib_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-3.14.6-30.fc33.noarch Additional info: component: selinux-policy reporter: libreport-2.14.0 hashmarkername: setroubleshoot kernel: 5.9.8-200.fc33.x86_64 type: libreport
This SELinux denial is already mentioned in https://bugzilla.redhat.com/show_bug.cgi?id=1899548#c2
*** This bug has been marked as a duplicate of bug 1900383 ***