Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: usbmuxd triggers 2 denials when an iOS device is plugged in Version-Release number of selected component (if applicable): selinux-policy.noarch 34.7-1.fc34 selinux-policy-targeted.noarch 34.7-1.fc34 usbmuxd 1.1.1-4.fc34 How reproducible: Always Steps to Reproduce: 1. make sure usbmuxd is running 2. plug in an unpaired iOS device 3. observe the denials Actual results: selinux denials Expected results: there should be no denials Additional info: I believe this is identical to #1959747 but that one was filed against rawhide. SELinux is preventing usbmuxd from search access on the directory 1. Plugin: catchall SELinux denied access requested by usbmuxd. It is not expected that this access is required by usbmuxd and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. If you believe that usbmuxd should be allowed search access on the 1 directory by default. You should report this as a bug. You can generate a local policy module to allow this access. Allow this access for now by executing: # ausearch -c 'usbmuxd' --raw | audit2allow -M my-usbmuxd # semodule -X 300 -i my-usbmuxd.pp --------------------- SELinux is preventing usbmuxd from getattr access on the filesystem /. Plugin: catchall SELinux denied access requested by usbmuxd. It is not expected that this access is required by usbmuxd and this access may signal an intrusion attempt. It is also possible that the specific version or configuration of the application is causing it to require additional access. If you believe that usbmuxd should be allowed getattr access on the filesystem by default. You should report this as a bug. You can generate a local policy module to allow this access. Allow this access for now by executing: # ausearch -c 'usbmuxd' --raw | audit2allow -M my-usbmuxd # semodule -X 300 -i my-usbmuxd.pp
Please collect the SELinux denials and attach them here: # ausearch -m avc -m user_avc -i -ts today Thank you.
Apologies about the delay. Here is the requested info: ---- type=AVC msg=audit(05/29/21 10:02:33.459:1469) : avc: denied { search } for pid=440579 comm=usbmuxd name=1 dev="proc" ino=17409 scontext=system_u:system_r:usbmuxd_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=dir permissive=0 ---- type=AVC msg=audit(05/29/21 10:02:33.459:1470) : avc: denied { getattr } for pid=440579 comm=usbmuxd name=/ dev="dm-1" ino=256 scontext=system_u:system_r:usbmuxd_t:s0 tcontext=system_u:object_r:fs_t:s0 tclass=filesystem permissive=0
Let's continue in the other bz. *** This bug has been marked as a duplicate of bug 1959747 ***