Bug 1926696 - SELinux prevents biosdecode, vpddecode, ownership tools from integrity on lockdown class
Summary: SELinux prevents biosdecode, vpddecode, ownership tools from integrity on loc...
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 34
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-02-09 09:51 UTC by Milos Malik
Modified: 2021-02-25 22:20 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2021-02-25 22:20:07 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Milos Malik 2021-02-09 09:51:25 UTC
Description of problem:
 * all 3 programs end with exit code 1 and error message

/dev/mem: Permission denied

Version-Release number of selected component (if applicable):
selinux-policy-3.14.7-18.fc34.noarch
selinux-policy-targeted-3.14.7-18.fc34.noarch
dmidecode-3.2-9.fc34.x86_64

How reproducible:
 * always

Steps to Reproduce:
1. get a Fedora rawhide machine (targeted policy is active)
2. run the following automated TC:
 * /CoreOS/selinux-policy/Regression/dmidecode-and-similar
3. search for SELinux denials

Actual results:
----
type=PROCTITLE msg=audit(02/08/2021 22:19:44.451:5700) : proctitle=/usr/sbin/biosdecode 
type=PATH msg=audit(02/08/2021 22:19:44.451:5700) : item=0 name=/dev/mem inode=3 dev=00:05 mode=character,640 ouid=root ogid=kmem rdev=01:01 obj=system_u:object_r:memory_device_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(02/08/2021 22:19:44.451:5700) : cwd=/mnt/tests/CoreOS/selinux-policy/Regression/dmidecode-and-similar 
type=SYSCALL msg=audit(02/08/2021 22:19:44.451:5700) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=0xffffff9c a1=0x564b69eb1279 a2=O_RDONLY a3=0x0 items=1 ppid=471969 pid=477116 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=9 comm=biosdecode exe=/usr/sbin/biosdecode subj=system_u:system_r:dmidecode_t:s0 key=(null) 
type=AVC msg=audit(02/08/2021 22:19:44.451:5700) : avc:  denied  { integrity } for  pid=477116 comm=biosdecode lockdown_reason="/dev/mem,kmem,port" scontext=system_u:system_r:dmidecode_t:s0 tcontext=system_u:system_r:dmidecode_t:s0 tclass=lockdown permissive=0 
----
type=PROCTITLE msg=audit(02/08/2021 22:19:44.557:5702) : proctitle=/usr/sbin/vpddecode 
type=PATH msg=audit(02/08/2021 22:19:44.557:5702) : item=0 name=/dev/mem inode=3 dev=00:05 mode=character,640 ouid=root ogid=kmem rdev=01:01 obj=system_u:object_r:memory_device_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(02/08/2021 22:19:44.557:5702) : cwd=/mnt/tests/CoreOS/selinux-policy/Regression/dmidecode-and-similar 
type=SYSCALL msg=audit(02/08/2021 22:19:44.557:5702) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=0xffffff9c a1=0x55ca4560e034 a2=O_RDONLY a3=0x0 items=1 ppid=471969 pid=477136 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=9 comm=vpddecode exe=/usr/sbin/vpddecode subj=system_u:system_r:dmidecode_t:s0 key=(null) 
type=AVC msg=audit(02/08/2021 22:19:44.557:5702) : avc:  denied  { integrity } for  pid=477136 comm=vpddecode lockdown_reason="/dev/mem,kmem,port" scontext=system_u:system_r:dmidecode_t:s0 tcontext=system_u:system_r:dmidecode_t:s0 tclass=lockdown permissive=0 
----
type=PROCTITLE msg=audit(02/08/2021 22:19:44.630:5703) : proctitle=/usr/sbin/ownership 
type=PATH msg=audit(02/08/2021 22:19:44.630:5703) : item=0 name=/dev/mem inode=3 dev=00:05 mode=character,640 ouid=root ogid=kmem rdev=01:01 obj=system_u:object_r:memory_device_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(02/08/2021 22:19:44.630:5703) : cwd=/mnt/tests/CoreOS/selinux-policy/Regression/dmidecode-and-similar 
type=SYSCALL msg=audit(02/08/2021 22:19:44.630:5703) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=0xffffff9c a1=0x5589badf703e a2=O_RDONLY a3=0x0 items=1 ppid=471969 pid=477155 auid=root uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=9 comm=ownership exe=/usr/sbin/ownership subj=system_u:system_r:dmidecode_t:s0 key=(null) 
type=AVC msg=audit(02/08/2021 22:19:44.630:5703) : avc:  denied  { integrity } for  pid=477155 comm=ownership lockdown_reason="/dev/mem,kmem,port" scontext=system_u:system_r:dmidecode_t:s0 tcontext=system_u:system_r:dmidecode_t:s0 tclass=lockdown permissive=0
----

Expected results:
 * no SELinux denials
 * all 3 tools work as expected

Comment 1 Zdenek Pytela 2021-02-09 11:17:42 UTC
I've submitted a Fedora PR to address the issue:
https://github.com/fedora-selinux/selinux-policy/pull/567

Comment 2 Ben Cotton 2021-02-09 16:24:43 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 34 development cycle.
Changing version to 34.

Comment 4 Zdenek Pytela 2021-02-25 22:20:07 UTC
Fixed in the latest package version.


Note You need to log in before you can comment on or make changes to this bug.