Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: The Spooks are fucking with me. # ausearch -c 'chronyd' --raw | audit2allow -M my-chronyd # semodule -X 300 -i my-chronyd.pp [wildegeist@cyber-abattoir ~]$ gcc gcc: fatal error: no input files compilation terminated. [wildegeist@cyber-abattoir ~]$ gccpp bash: gccpp: command not found [wildegeist@cyber-abattoir ~]$ pp,ping bash: pp,ping: command not found [wildegeist@cyber-abattoir ~]$ ping ping: usage error: Destination address required [wildegeist@cyber-abattoir ~]$ semodule x300-i-my-rsyslog.pp At least one mode must be specified. usage: semodule [option]... MODE... Manage SELinux policy modules. MODES: -R, --reload reload policy -B, --build build and reload policy -D,--disable_dontaudit Remove dontaudits from policy -i,--install=MODULE_PKG install a new module -r,--remove=MODULE_NAME remove existing module at desired priority -l[KIND],--list-modules[=KIND] display list of installed modules KIND: standard list highest priority, enabled modules full list all modules -X,--priority=PRIORITY set priority for following operations (1-999) -e,--enable=MODULE_NAME enable module -d,--disable=MODULE_NAME disable module -E,--extract=MODULE_NAME extract module Options: -s,--store name of the store to operate on -N,-n,--noreload do not reload policy after commit -h,--help print this message and quit -v,--verbose be verbose -P,--preserve_tunables Preserve tunables in policy -C,--ignore-module-cache Rebuild CIL modules compiled from HLL files -p,--path use an alternate path for the policy root -S,--store-path use an alternate path for the policy store root -c, --cil extract module as cil. This only affects module extraction. -H, --hll extract module as hll. This only affects module extraction. [wildegeist@cyber-abattoir ~]$ reload bash: reload: command not found [wildegeist@cyber-abattoir ~]$ SELinux is preventing chronyd from 'write' accesses on the sock_file io.systemd.Resolve. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that chronyd should be allowed write access on the io.systemd.Resolve sock_file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'chronyd' --raw | audit2allow -M my-chronyd # semodule -X 300 -i my-chronyd.pp Additional Information: Source Context system_u:system_r:chronyd_t:s0 Target Context system_u:object_r:systemd_resolved_var_run_t:s0 Target Objects io.systemd.Resolve [ sock_file ] Source chronyd Source Path chronyd Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-3.14.7-8.fc34.noarch Local Policy RPM selinux-policy-targeted-3.14.7-8.fc34.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 5.10.0-0.rc4.20201119gitc2e7554e1b 85.81.fc34.x86_64 #1 SMP Thu Nov 19 20:45:31 UTC 2020 x86_64 x86_64 Alert Count 18 First Seen 2020-12-12 22:22:53 CST Last Seen 2020-12-12 22:59:28 CST Local ID 472410d9-7f0a-47d5-ad0a-3d102c3409bc Raw Audit Messages type=AVC msg=audit(1607835568.68:570): avc: denied { write } for pid=638 comm="chronyd" name="io.systemd.Resolve" dev="tmpfs" ino=1146 scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=sock_file permissive=0 Hash: chronyd,chronyd_t,systemd_resolved_var_run_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-3.14.7-8.fc34.noarch Additional info: component: selinux-policy reporter: libreport-2.14.0 hashmarkername: setroubleshoot kernel: 5.10.0-0.rc4.20201119gitc2e7554e1b85.81.fc34.x86_64 type: libreport Potential duplicate: bug 1900143
Yes, this bug is a duplicate of BZ#1900143.
*** This bug has been marked as a duplicate of bug 1900143 ***