Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pressure. ***** Plugin catchall (100. confidence) suggests ************************** Wenn Sie denken, dass es mariadbd standardmäßig erlaubt sein sollte, write Zugriff auf memory.pressure file zu erhalten. Then sie sollten dies als Fehler melden. Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen. Do zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen: # ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd # semodule -X 300 -i my-mariadbd.pp Additional Information: Source Context system_u:system_r:mysqld_t:s0 Target Context system_u:object_r:cgroup_t:s0 Target Objects memory.pressure [ file ] Source mariadbd Source Path mariadbd Port <Unbekannt> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-39.3-1.fc39.noarch Local Policy RPM selinux-policy-targeted-39.3-1.fc39.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.6.8-200.fc39.x86_64 #1 SMP PREEMPT_DYNAMIC Thu Dec 21 04:01:49 UTC 2023 x86_64 Alert Count 9 First Seen 2023-12-26 12:02:04 CET Last Seen 2023-12-27 18:29:29 CET Local ID 826f3f56-06b3-416a-917f-8bf68259e820 Raw Audit Messages type=AVC msg=audit(1703698169.182:144): avc: denied { write } for pid=2521 comm="mariadbd" name="memory.pressure" dev="cgroup2" ino=6338 scontext=system_u:system_r:mysqld_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=0 Hash: mariadbd,mysqld_t,cgroup_t,file,write Version-Release number of selected component: selinux-policy-targeted-39.3-1.fc39.noarch Additional info: reporter: libreport-2.17.11 reason: SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pressure. package: selinux-policy-targeted-39.3-1.fc39.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.6.8-200.fc39.x86_64 component: selinux-policy
Created attachment 2006123 [details] File: description
Created attachment 2006124 [details] File: os_info
*** Bug 2257049 has been marked as a duplicate of this bug. ***
*** Bug 2256274 has been marked as a duplicate of this bug. ***
Same error is occurring in Fedora 40: SELinux is preventing mariadbd from write access on the file memory.pressure. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that mariadbd should be allowed write access on the memory.pressure file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd # semodule -X 300 -i my-mariadbd.pp Additional Information: Source Context system_u:system_r:mysqld_t:s0 Target Context system_u:object_r:cgroup_t:s0 Target Objects memory.pressure [ file ] Source mariadbd Source Path mariadbd Port <Unknown> Host cipix Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.23-1.fc40.noarch Local Policy RPM mysql-selinux-1.0.10-3.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name cipix Platform Linux cipix 6.9.5-200.fc40.x86_64 #1 SMP PREEMPT_DYNAMIC Sun Jun 16 15:47:09 UTC 2024 x86_64 Alert Count 8 First Seen 2024-07-03 23:54:37 MST Last Seen 2024-07-14 15:59:17 MST Local ID 76778e88-f058-4a74-bbfa-23ea11a5d896 Raw Audit Messages type=AVC msg=audit(1720997957.815:231): avc: denied { write } for pid=7338 comm="mariadbd" name="memory.pressure" dev="cgroup2" ino=13132 scontext=system_u:system_r:mysqld_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=0 Hash: mariadbd,mysqld_t,cgroup_t,file,write
Same problem here. The suggestion to allow access via ´´´ # ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd # semodule -X 300 -i my-mariadbd.pp ´´´ didn't really solve the issue. While SELinux is not complaining anymore, MariaDB startup fails with the exact same error as before. ´´´ # systemctl status mariadb × mariadb.service - MariaDB 10.11 database server Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled) Drop-In: /usr/lib/systemd/system/service.d └─10-timeout-abort.conf Active: failed (Result: exit-code) since Thu 2024-07-18 14:51:17 CEST; 8min ago Docs: man:mariadbd(8) https://mariadb.com/kb/en/library/systemd/ Process: 26529 ExecStartPre=/usr/libexec/mariadb-check-socket (code=exited, status=0/SUCCESS) Process: 26555 ExecStartPre=/usr/libexec/mariadb-prepare-db-dir mariadb.service (code=exited, status=0/SUCCESS) Process: 26591 ExecStart=/usr/libexec/mariadbd --basedir=/usr $MYSQLD_OPTS $_WSREP_NEW_CLUSTER (code=exited, status=1/FAILURE) Main PID: 26591 (code=exited, status=1/FAILURE) Status: "MariaDB server is down" CPU: 161ms # journalctl -xeu mariadb.service Jul 18 14:51:16 foras systemd[1]: Starting mariadb.service - MariaDB 10.11 database server... ░░ Subject: A start job for unit mariadb.service has begun execution ░░ Defined-By: systemd ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel ░░ ░░ A start job for unit mariadb.service has begun execution. ░░ ░░ The job identifier is 9176. Jul 18 14:51:16 foras mariadb-check-socket[26529]: Socket file /var/lib/mysql/mysql.sock exists. Jul 18 14:51:16 foras mariadb-check-socket[26529]: No process is using /var/lib/mysql/mysql.sock, which means it is a garbage, so it will be removed automatically. Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: Database MariaDB is probably initialized in /var/lib/mysql already, nothing is done. Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: If this is not the case, make sure the /var/lib/mysql is empty before running mariadb-prepare-db-dir. Jul 18 14:51:16 foras (mariadbd)[26591]: mariadb.service: Referenced but unset environment variable evaluates to an empty string: MYSQLD_OPTS, _WSREP_NEW_CLUSTER Jul 18 14:51:17 foras systemd[1]: mariadb.service: Main process exited, code=exited, status=1/FAILURE ░░ Subject: Unit process exited ░░ Defined-By: systemd ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel ░░ ░░ An ExecStart= process belonging to unit mariadb.service has exited. ░░ ░░ The process' exit code is 'exited' and its exit status is 1. Jul 18 14:51:17 foras systemd[1]: mariadb.service: Failed with result 'exit-code'. ░░ Subject: Unit failed ░░ Defined-By: systemd ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel ░░ ░░ The unit mariadb.service has entered the 'failed' state with result 'exit-code'. Jul 18 14:51:17 foras systemd[1]: Failed to start mariadb.service - MariaDB 10.11 database server. ░░ Subject: A start job for unit mariadb.service has failed ░░ Defined-By: systemd ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel ░░ ░░ A start job for unit mariadb.service has finished with a failure. ░░ ░░ The job identifier is 9176 and the job result is failed. ``` Doesn't this suggest the real problem has something to do with `Referenced but unset environment variable evaluates to an empty string: MYSQLD_OPTS, _WSREP_NEW_CLUSTER`?
(In reply to Timm Fitschen from comment #6) > Same problem here. > > The suggestion to allow access via > > ´´´ > # ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd > # semodule -X 300 -i my-mariadbd.pp > ´´´ > > didn't really solve the issue. While SELinux is not complaining anymore, > MariaDB startup fails with the exact same error as before. > > ´´´ > # systemctl status mariadb > × mariadb.service - MariaDB 10.11 database server > Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; > preset: disabled) > Drop-In: /usr/lib/systemd/system/service.d > └─10-timeout-abort.conf > Active: failed (Result: exit-code) since Thu 2024-07-18 14:51:17 CEST; > 8min ago > Docs: man:mariadbd(8) > https://mariadb.com/kb/en/library/systemd/ > Process: 26529 ExecStartPre=/usr/libexec/mariadb-check-socket > (code=exited, status=0/SUCCESS) > Process: 26555 ExecStartPre=/usr/libexec/mariadb-prepare-db-dir > mariadb.service (code=exited, status=0/SUCCESS) > Process: 26591 ExecStart=/usr/libexec/mariadbd --basedir=/usr > $MYSQLD_OPTS $_WSREP_NEW_CLUSTER (code=exited, status=1/FAILURE) > Main PID: 26591 (code=exited, status=1/FAILURE) > Status: "MariaDB server is down" > CPU: 161ms > > > # journalctl -xeu mariadb.service > Jul 18 14:51:16 foras systemd[1]: Starting mariadb.service - MariaDB 10.11 > database server... > ░░ Subject: A start job for unit mariadb.service has begun execution > ░░ Defined-By: systemd > ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel > ░░ > ░░ A start job for unit mariadb.service has begun execution. > ░░ > ░░ The job identifier is 9176. > Jul 18 14:51:16 foras mariadb-check-socket[26529]: Socket file > /var/lib/mysql/mysql.sock exists. > Jul 18 14:51:16 foras mariadb-check-socket[26529]: No process is using > /var/lib/mysql/mysql.sock, which means it is a garbage, so it will be > removed automatically. > Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: Database MariaDB is > probably initialized in /var/lib/mysql already, nothing is done. > Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: If this is not the > case, make sure the /var/lib/mysql is empty before running > mariadb-prepare-db-dir. > Jul 18 14:51:16 foras (mariadbd)[26591]: mariadb.service: Referenced but > unset environment variable evaluates to an empty string: MYSQLD_OPTS, > _WSREP_NEW_CLUSTER > Jul 18 14:51:17 foras systemd[1]: mariadb.service: Main process exited, > code=exited, status=1/FAILURE > ░░ Subject: Unit process exited > ░░ Defined-By: systemd > ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel > ░░ > ░░ An ExecStart= process belonging to unit mariadb.service has exited. > ░░ > ░░ The process' exit code is 'exited' and its exit status is 1. > Jul 18 14:51:17 foras systemd[1]: mariadb.service: Failed with result > 'exit-code'. > ░░ Subject: Unit failed > ░░ Defined-By: systemd > ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel > ░░ > ░░ The unit mariadb.service has entered the 'failed' state with result > 'exit-code'. > Jul 18 14:51:17 foras systemd[1]: Failed to start mariadb.service - MariaDB > 10.11 database server. > ░░ Subject: A start job for unit mariadb.service has failed > ░░ Defined-By: systemd > ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel > ░░ > ░░ A start job for unit mariadb.service has finished with a failure. > ░░ > ░░ The job identifier is 9176 and the job result is failed. > ``` > > Doesn't this suggest the real problem has something to do with `Referenced > but unset environment variable evaluates to an empty string: MYSQLD_OPTS, > _WSREP_NEW_CLUSTER`? On further investigation, I found that MariaDB wouldn't start because of ``` 2024-07-18 14:51:16 0 [ERROR] InnoDB: Upgrade after a crash is not supported. The redo log was created with MariaDB 10.5.16. You must start up and shut down MariaDB 10.7 or earlier. ``` So I did as recommended: downgrade to mariadb-10.5.23, then start and stop mariadb. then update mariadb to 10.11 again. start mariadb-10.11 -- everything worked fine, so I finally disabled the SELinux policy with `semodule -d my-mariadbd`. So I ended up with the following situation: 1) I am able to start mariadb via systemctl and it is working fine. 2) But SELinux is complaining again that "SELinux is preventing mariadbd from write access on the file memory.pressure." without further negative implications for now. I hope this helps.
FEDORA-2024-3721532bce (mysql-selinux-1.0.11-1.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2024-3721532bce
FEDORA-2024-28bb0038ce (mysql-selinux-1.0.11-1.fc39) has been submitted as an update to Fedora 39. https://bodhi.fedoraproject.org/updates/FEDORA-2024-28bb0038ce
FEDORA-2024-4f35baf4d4 (mysql-selinux-1.0.11-1.fc41) has been submitted as an update to Fedora 41. https://bodhi.fedoraproject.org/updates/FEDORA-2024-4f35baf4d4
FEDORA-2024-4f35baf4d4 has been pushed to the Fedora 41 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-4f35baf4d4` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-4f35baf4d4 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2024-28bb0038ce has been pushed to the Fedora 39 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-28bb0038ce` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-28bb0038ce See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2024-3721532bce has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-3721532bce` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-3721532bce See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2024-4f35baf4d4 (mysql-selinux-1.0.11-1.fc41) has been pushed to the Fedora 41 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2024-28bb0038ce (mysql-selinux-1.0.11-1.fc39) has been pushed to the Fedora 39 stable repository. If problem still persists, please make note of it in this bug report.
FEDORA-2024-3721532bce (mysql-selinux-1.0.11-1.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report.