Bug 2181402 - qemu-guest-agent couldn't write ssh-key to normal user
Summary: qemu-guest-agent couldn't write ssh-key to normal user
Keywords:
Status: VERIFIED
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: selinux-policy
Version: 9.2
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: rc
: ---
Assignee: Nikola Knazekova
QA Contact: Milos Malik
URL:
Whiteboard:
Depends On:
Blocks: 2226685
TreeView+ depends on / blocked
 
Reported: 2023-03-24 03:03 UTC by dehanmeng
Modified: 2023-08-06 14:14 UTC (History)
11 users (show)

Fixed In Version: selinux-policy-38.1.18-1.el9
Doc Type: No Doc Update
Doc Text:
Clone Of:
: 2226685 (view as bug list)
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-152960 0 None None None 2023-03-24 03:06:39 UTC

Comment 1 Milos Malik 2023-03-24 07:59:51 UTC
Please collect SELinux denials that appeared during the Steps to Reproduce.

# ausearch -m avc -m user_avc -m selinux_err -i -ts today

And attach them to this BZ.

Thank you.

Did the /home/fedora/.ssh directory exist before Steps to Reproduce?

Comment 2 Renaud Métrich 2023-03-24 09:19:42 UTC
You may also strace qemu-ga with SELinux contexts, very useful for debugging:

# strace -fttTvyy -s 128 --secontext=all -o qemu-ga.strace -p $(pgrep qemu-ga)

Using "all" will shows full context + eventual mismatches (just in case some file is not labeled properly, to avoid false positives).

Comment 4 dehanmeng 2023-03-27 02:42:50 UTC
(In reply to Milos Malik from comment #1)
> Please collect SELinux denials that appeared during the Steps to Reproduce.
> 
> # ausearch -m avc -m user_avc -m selinux_err -i -ts today
> 
> And attach them to this BZ.

attachment has been updated and named as 'denied.txt'.
> 
> Thank you.
> 
> Did the /home/fedora/.ssh directory exist before Steps to Reproduce?

Definitely yes.

Comment 17 Nikola Knazekova 2023-06-14 15:56:48 UTC
Thank you. 

What is the output of this? 
# ausearch -m avc -ts today | audit2allow

Comment 19 Nikola Knazekova 2023-06-19 12:08:51 UTC
Thank you, 

Can you please enable the boolean:
# semanage boolean -m --on virt_qemu_ga_manage_ssh

and run your tests, in both SELinux modes: 
enforcing: # setenforce 1

then permissive: # setenforce 0

And check denials?

Comment 21 Nikola Knazekova 2023-07-03 08:22:44 UTC
Thank you,

PR: https://github.com/fedora-selinux/selinux-policy/pull/1772

Comment 37 Nikola Knazekova 2023-07-24 11:23:19 UTC
PR with new fixes is merged: https://github.com/fedora-selinux/selinux-policy/pull/1788.

Commits to backport:
4cffc71d2 Boolean: Allow virt_qemu_ga create ssh directory
19e34245f Allow virt_qemu_ga_t create .ssh dir with correct label


Note You need to log in before you can comment on or make changes to this bug.