Bug 1963065 - SELinux is preventing rpcbind from 'name_bind' accesses on the udp_socket porte 65222.
Summary: SELinux is preventing rpcbind from 'name_bind' accesses on the udp_socket por...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 34
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:353bb6bd6a8e04006146647683a...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-05-21 10:52 UTC by Davide Repetto
Modified: 2022-05-11 11:29 UTC (History)
11 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-05-11 11:29:21 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Davide Repetto 2021-05-21 10:52:10 UTC
Description of problem:
This happened during today's upgrade:

[root@dave ~]# dnf history info last
ID transazione : 109
Ora inizio     : ven 21 mag 2021, 12:37:25
rpmdb iniziale : 4591:374b51db16652c4ab34b2c955f175037752a0a57
Ora termine    : ven 21 mag 2021, 12:37:52 (27 secondi)
rpmdb finale   : 4591:d8ec94538ae7f149fe1b39a908d9b7fae822bd65
Utente         : Davide <davide>
Codice di uscita    : Completato
Rilascio: 34
Linea di comando   : -y upgrade
Commento        : 
Pacchetti modificati:
    Upgrade  chrony-4.1-1.fc34.x86_64                     @updates
    Upgraded chrony-4.0-3.fc34.x86_64                     @@System
    Upgrade  fpaste-0.4.2.0-1.fc34.noarch                 @updates
    Upgraded fpaste-0.4.1.1-2.fc34.noarch                 @@System
    Upgrade  fuse-common-3.10.3-1.fc34.x86_64             @updates
    Upgraded fuse-common-3.10.2-1.fc34.x86_64             @@System
    Upgrade  fuse3-3.10.3-1.fc34.x86_64                   @updates
    Upgraded fuse3-3.10.2-1.fc34.x86_64                   @@System
    Upgrade  fuse3-libs-3.10.3-1.fc34.x86_64              @updates
    Upgraded fuse3-libs-3.10.2-1.fc34.x86_64              @@System
    Upgrade  libibumad-35.0-1.fc34.x86_64                 @updates
    Upgraded libibumad-34.0-3.fc34.x86_64                 @@System
    Upgrade  libibverbs-35.0-1.fc34.i686                  @updates
    Upgraded libibverbs-34.0-3.fc34.i686                  @@System
    Upgrade  libibverbs-35.0-1.fc34.x86_64                @updates
    Upgraded libibverbs-34.0-3.fc34.x86_64                @@System
    Upgrade  libidn2-2.3.1-1.fc34.i686                    @updates
    Upgraded libidn2-2.3.0-5.fc34.i686                    @@System
    Upgrade  libidn2-2.3.1-1.fc34.x86_64                  @updates
    Upgraded libidn2-2.3.0-5.fc34.x86_64                  @@System
    Upgrade  librados2-2:16.2.4-1.fc34.x86_64             @updates
    Upgraded librados2-2:16.2.1-1.fc34.x86_64             @@System
    Upgrade  librbd1-2:16.2.4-1.fc34.x86_64               @updates
    Upgraded librbd1-2:16.2.1-1.fc34.x86_64               @@System
    Upgrade  librdmacm-35.0-1.fc34.x86_64                 @updates
    Upgraded librdmacm-34.0-3.fc34.x86_64                 @@System
    Upgrade  libtirpc-1.3.2-0.fc34.i686                   @updates
    Upgraded libtirpc-1.3.1-1.rc2.fc34.i686               @@System
    Upgrade  libtirpc-1.3.2-0.fc34.x86_64                 @updates
    Upgraded libtirpc-1.3.1-1.rc2.fc34.x86_64             @@System
    Upgrade  lohit-devanagari-fonts-2.95.5-1.fc34.noarch  @updates
    Upgraded lohit-devanagari-fonts-2.95.4-12.fc34.noarch @@System
    Upgrade  rdma-core-35.0-1.fc34.x86_64                 @updates
    Upgraded rdma-core-34.0-3.fc34.x86_64                 @@System
    Upgrade  rpcbind-1.2.6-0.fc34.x86_64                  @updates
    Upgraded rpcbind-1.2.5-5.rc1.fc34.4.x86_64            @@System
    Upgrade  wpebackend-fdo-1.9.92-1.fc34.x86_64          @updates
    Upgraded wpebackend-fdo-1.9.91-1.fc34.x86_64          @@System
Output dello scriptlet:
   1 Job failed. See "journalctl -xe" for details.
   2 A dependency job for rpcbind.service failed. See 'journalctl -xe' for details.
SELinux is preventing rpcbind from 'name_bind' accesses on the udp_socket porte 65222.

*****  Plugin bind_ports (92.2 confidence) suggests   ************************

Se vuoi permettere rpcbind per collegarsi alla porta di rete $PORT_NUMERO
Then you need to modify the port type.
Do
# semanage port -a -t PORT_TYPE -p udp 65222
dove PORT_TYPE è una delle seguenti: agentx_port_t, apertus_ldp_port_t, comsat_port_t, dhcpc_port_t, dhcpd_port_t, dns_port_t, efs_port_t, flash_port_t, ftp_port_t, gdomap_port_t, hi_reserved_port_t, inetd_child_port_t, ipmi_port_t, ipp_port_t, kerberos_admin_port_t, kerberos_port_t, kprop_port_t, ktalkd_port_t, ldap_port_t, pki_ca_port_t, pop_port_t, portmap_port_t, printer_port_t, rlogin_port_t, rlogind_port_t, rndc_port_t, router_port_t, rsh_port_t, rsync_port_t, rtsp_port_t, rwho_port_t, smtp_port_t, spamd_port_t, swat_port_t, syslogd_port_t, uucpd_port_t.

*****  Plugin catchall_boolean (7.83 confidence) suggests   ******************

Se lo desidera allow nis to enabled
Then è necessario informare SELinux abilitando il booleano 'nis_enabled' .

Do
setsebool -P nis_enabled 1

*****  Plugin catchall (1.41 confidence) suggests   **************************

Se ci credi rpcbind dovrebbe essere consentito name_bind accesso al porte 65222 udp_socket per impostazione predefinita.
Then si dovrebbe riportare il problema come bug.
E' possibile generare un modulo di politica locale per consentire questo accesso.
Do
consentire questo accesso per ora eseguendo:
# ausearch -c 'rpcbind' --raw | audit2allow -M my-$MODULE_NOME
# semodule -X 300 -i miei-rpcbind.pp

Additional Information:
Source Context                system_u:system_r:rpcbind_t:s0
Target Context                system_u:object_r:unreserved_port_t:s0
Target Objects                porte 65222 [ udp_socket ]
Source                        rpcbind
Source Path                   rpcbind
Port                          65222
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-34.7-1.fc34.noarch
Local Policy RPM              selinux-policy-targeted-34.7-1.fc34.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Permissive
Host Name                     (removed)
Platform                      Linux (removed) 5.11.21-300.fc34.x86_64 #1 SMP Fri
                              May 14 17:43:38 UTC 2021 x86_64 x86_64
Alert Count                   3
First Seen                    2021-05-21 12:37:30 CEST
Last Seen                     2021-05-21 12:37:39 CEST
Local ID                      39956b1d-cacf-4430-b75e-a5ca57d17547

Raw Audit Messages
type=AVC msg=audit(1621593459.730:1640): avc:  denied  { name_bind } for  pid=75590 comm="rpcbind" src=65222 scontext=system_u:system_r:rpcbind_t:s0 tcontext=system_u:object_r:unreserved_port_t:s0 tclass=udp_socket permissive=1


Hash: rpcbind,rpcbind_t,unreserved_port_t,udp_socket,name_bind

Version-Release number of selected component:
selinux-policy-targeted-34.7-1.fc34.noarch

Additional info:
component:      selinux-policy
reporter:       libreport-2.14.0
hashmarkername: setroubleshoot
kernel:         5.11.21-300.fc34.x86_64
type:           libreport

Potential duplicate: bug 1889164

Comment 1 Andrew 2021-08-10 13:05:47 UTC
Seems same: bug #1758147

Comment 2 Mai Ling 2021-10-30 08:38:19 UTC
Similar problem has been detected:

appeared when I started autofs and attempted to access the remote share

hashmarkername: setroubleshoot
kernel:         5.13.12-200.fc34.x86_64
package:        selinux-policy-targeted-34.16-1.fc34.noarch
reason:         SELinux is preventing rpcbind from 'name_bind' accesses on the udp_socket port 61331.
type:           libreport


Note You need to log in before you can comment on or make changes to this bug.