Bug 1964993 - usbmuxd triggers two denials
Summary: usbmuxd triggers two denials
Keywords:
Status: CLOSED DUPLICATE of bug 1959747
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 34
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-05-26 13:41 UTC by Alice McLafferty
Modified: 2021-06-04 19:31 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2021-06-04 19:31:20 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Alice McLafferty 2021-05-26 13:41:28 UTC
Description of problem:
usbmuxd triggers 2 denials when an iOS device is plugged in

Version-Release number of selected component (if applicable):
selinux-policy.noarch              34.7-1.fc34
selinux-policy-targeted.noarch     34.7-1.fc34
usbmuxd                            1.1.1-4.fc34

How reproducible:
Always

Steps to Reproduce:
1. make sure usbmuxd is running
2. plug in an unpaired iOS device
3. observe the denials

Actual results:
selinux denials

Expected results:
there should be no denials

Additional info:
I believe this is identical to #1959747 but that one was filed against rawhide.

SELinux is preventing usbmuxd from search access on the directory 1.

Plugin: catchall 
 SELinux denied access requested by usbmuxd. It is not expected that this access
is required by usbmuxd and this access may signal an intrusion attempt. It is
also possible that the specific version or configuration of the application is
causing it to require additional access.

If you believe that usbmuxd should be allowed search access on the 1 directory by default.
You should report this as a bug.
You can generate a local policy module to allow this access.
Allow this access for now by executing:
# ausearch -c 'usbmuxd' --raw | audit2allow -M my-usbmuxd
# semodule -X 300 -i my-usbmuxd.pp

---------------------

SELinux is preventing usbmuxd from getattr access on the filesystem /.

Plugin: catchall 
 SELinux denied access requested by usbmuxd. It is not expected that this access
is required by usbmuxd and this access may signal an intrusion attempt. It is
also possible that the specific version or configuration of the application is
causing it to require additional access.

If you believe that usbmuxd should be allowed getattr access on the  filesystem by default.
You should report this as a bug.
You can generate a local policy module to allow this access.
Allow this access for now by executing:
# ausearch -c 'usbmuxd' --raw | audit2allow -M my-usbmuxd
# semodule -X 300 -i my-usbmuxd.pp

Comment 1 Milos Malik 2021-05-26 13:50:44 UTC
Please collect the SELinux denials and attach them here:

# ausearch -m avc -m user_avc -i -ts today

Thank you.

Comment 2 Alice McLafferty 2021-05-29 14:56:35 UTC
Apologies about the delay. Here is the requested info:

----
type=AVC msg=audit(05/29/21 10:02:33.459:1469) : avc:  denied  { search } for  pid=440579 comm=usbmuxd name=1 dev="proc" ino=17409 scontext=system_u:system_r:usbmuxd_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=dir permissive=0 
----
type=AVC msg=audit(05/29/21 10:02:33.459:1470) : avc:  denied  { getattr } for  pid=440579 comm=usbmuxd name=/ dev="dm-1" ino=256 scontext=system_u:system_r:usbmuxd_t:s0 tcontext=system_u:object_r:fs_t:s0 tclass=filesystem permissive=0

Comment 3 Zdenek Pytela 2021-06-04 19:31:20 UTC
Let's continue in the other bz.

*** This bug has been marked as a duplicate of bug 1959747 ***


Note You need to log in before you can comment on or make changes to this bug.