Bug 2056207 - systemd-sysctl was denied reading suid_dumpable, protected_hardlinks, and protected_symlinks by SELinux when booting Fedora 36
Summary: systemd-sysctl was denied reading suid_dumpable, protected_hardlinks, and pro...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 36
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2022-02-19 20:03 UTC by Matt Fagnani
Modified: 2022-03-24 19:33 UTC (History)
9 users (show)

Fixed In Version: selinux-policy-36.5-1.fc36
Clone Of:
Environment:
Last Closed: 2022-03-24 19:33:56 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 1089 0 None Merged Allow systemd-sysctl read the security state information 2022-02-23 12:47:15 UTC

Internal Links: 2056999

Description Matt Fagnani 2022-02-19 20:03:07 UTC
Description of problem:

I booted a Fedora 36 KDE Plasma installation after upgrading from Fedora 35.
systemd-sysctl was denied reading suid_dumpable, protected_hardlinks, and protected_symlinks by SELinux when booting Fedora 36.

Feb 19 14:19:22 systemd[1]: Starting systemd-sysctl.service - Apply Kernel Variables...
Feb 19 14:19:22 systemd[1]: systemd-sysusers.service - Create System Users was skipped because of a failed condition check (ConditionNeedsUpdate=/etc).
Feb 19 14:19:22 systemd[1]: Starting systemd-tmpfiles-setup-dev.service - Create Static Device Nodes in /dev...
Feb 19 14:19:22 systemd-journald[631]: Time spent on flushing to /var/log/journal/cf0bf479bcf04633b727cb244f663cd7 is 98.876ms for 1356 entries.
Feb 19 14:19:22 systemd-journald[631]: System Journal (/var/log/journal/cf0bf479bcf04633b727cb244f663cd7) is 2.2G, max 4.0G, 1.7G free.
Feb 19 14:19:22 systemd-journald[631]: Received client request to flush runtime journal.
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="suid_dumpable" dev="proc" ino=400 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80102 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="suid_dumpable" dev="proc" ino=400 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80000 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="protected_hardlinks" dev="proc" ino=419 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80102 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="protected_hardlinks" dev="proc" ino=419 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80000 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="protected_symlinks" dev="proc" ino=420 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80102 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"
Feb 19 14:19:22 audit[641]: AVC avc:  denied  { read } for  pid=641 comm="systemd-sysctl" name="protected_symlinks" dev="proc" ino=420 scontext=system_u:system_r:systemd_sysctl_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0
Feb 19 14:19:22 audit[641]: SYSCALL arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7ffd162b13d0 a2=80000 a3=0 items=0 ppid=1 pid=641 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-sysctl" exe="/usr/lib/systemd/systemd-sysctl" subj=system_u:system_r:systemd_sysctl_t:s0 key=(null)
Feb 19 14:19:22 audit: PROCTITLE proctitle="/usr/lib/systemd/systemd-sysctl"

I also saw these denials on a few boots of the live image Fedora-KDE-Live-x86_64-36-20220215.n.0.iso https://koji.fedoraproject.org/koji/buildinfo?buildID=1918275. I'm using the targeted policy in enforcing mode.

Version-Release number of selected component (if applicable):
selinux-policy-36.2-2.fc36.noarch
systemd-udev-250.3-4.fc36.x86_64

How reproducible:
These denials happened on each of several boots of Fedora 36 KDE Plasma installation and Fedora-KDE-Live-x86_64-36-20220215.n.0.iso

Steps to Reproduce:
1. Boot a Fedora 36 KDE Plasma installation updated to 2022-2-19 or Fedora-KDE-Live-x86_64-36-20220215.n.0.iso

Actual results:
systemd-sysctl was denied reading suid_dumpable, protected_hardlinks, and protected_symlinks by SELinux when booting Fedora 36.

Expected results:
No denials would happen.

Additional info:
The denials didn't appear in the SELinux troubleshoot GUI or as SELinux alert notifications in Plasma.

Comment 1 Zdenek Pytela 2022-02-21 11:57:37 UTC
I've submitted a Fedora PR to address the issue:
https://github.com/fedora-selinux/selinux-policy/pull/1089

Comment 2 Milos Malik 2022-02-23 09:51:58 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/277

The PR waits for review.

Comment 4 Zdenek Pytela 2022-02-24 19:49:32 UTC
(In reply to Jelle van der Waa from comment #3)
> This also occurs on rhel-9-0
> https://logs.cockpit-project.org/logs/pull-2995-20220224-024319-307fc473-
> rhel-9-0-cockpit-project-cockpit/log.html#268

Yes, refer to bz#2056999

Comment 5 Fedora Update System 2022-03-21 11:09:53 UTC
FEDORA-2022-b0805acc47 has been submitted as an update to Fedora 36. https://bodhi.fedoraproject.org/updates/FEDORA-2022-b0805acc47

Comment 6 Fedora Update System 2022-03-21 15:49:54 UTC
FEDORA-2022-b0805acc47 has been pushed to the Fedora 36 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --advisory=FEDORA-2022-b0805acc47`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2022-b0805acc47

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2022-03-24 19:33:56 UTC
FEDORA-2022-b0805acc47 has been pushed to the Fedora 36 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.