Bug 1991077 - AVC avc: denied { read } for pid=3083 comm="systemd-gpt-aut" name="b8:1" dev="tmpfs"
Summary: AVC avc: denied { read } for pid=3083 comm="systemd-gpt-aut" name="b8:1" d...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 35
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-08-07 03:28 UTC by Chris Murphy
Modified: 2022-09-12 15:19 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2022-09-12 15:19:00 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
journalctl (345.23 KB, text/plain)
2021-08-07 03:28 UTC, Chris Murphy
no flags Details

Description Chris Murphy 2021-08-07 03:28:12 UTC
Created attachment 1811731 [details]
journalctl

Description of problem:

Getting an AVC denial and subsequent systemd-gpt-auto-generator failure.


Version-Release number of selected component (if applicable):
systemd-249.2-1.fc35.x86_64
selinux-policy-34.14-2.fc35.noarch


How reproducible:
Transient but often


Steps to Reproduce:
1. Boot
2.
3.

Actual results:

Aug 06 22:51:41 fmac.local audit[3083]: AVC avc:  denied  { read } for  pid=3083 comm="systemd-gpt-aut" name="b8:1" dev="tmpfs" ino=1047 scontext=system_u:system_r:systemd_gpt_generator_t:s0 tcontext=system_u:object_r:udev_var_run_t:s0 tclass=file permissive=0
Aug 06 22:51:41 fmac.local systemd-gpt-auto-generator[3083]: Failed to dissect: Permission denied
Aug 06 22:51:41 fmac.local systemd[3067]: /usr/lib/systemd/system-generators/systemd-gpt-auto-generator failed with exit status 1.


Expected results:

It probably should be allowed


Additional info:

Comment 1 Chris Murphy 2021-08-07 03:41:33 UTC
Ordinarily this release criterion's "notification" is considered to be a desktop notification. https://fedoraproject.org/wiki/Fedora_35_Final_Release_Criteria#SELinux_and_crash_notifications
However, I think Fedora CoreOS makes use of Discoverable Partitions Spec? Or intends to? If so then this could be argued to be a blocker, since in that case the mechanism of notification is such an AVC denial appearing in the journal. For everything else, as far as I know, we're not using discoverable partition spec (yet).

Comment 2 Ben Cotton 2021-08-10 13:36:18 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 35 development cycle.
Changing version to 35.

Comment 3 Zdenek Pytela 2022-09-12 15:19:00 UTC
This bz has been fixed in F35.


Note You need to log in before you can comment on or make changes to this bug.