Bug 2256002 - SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pressure.
Summary: SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pres...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: mysql-selinux
Version: 39
Hardware: x86_64
OS: Unspecified
medium
unspecified
Target Milestone: ---
Assignee: Michal Schorm
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:2a51c9f7bff4129d178f8633ae1...
: 2256274 2257049 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-12-27 17:31 UTC by aannoaanno
Modified: 2024-09-26 02:44 UTC (History)
19 users (show)

Fixed In Version: mysql-selinux-1.0.11-1.fc41 mysql-selinux-1.0.11-1.fc39 mysql-selinux-1.0.11-1.fc40
Clone Of:
Environment:
Last Closed: 2024-09-25 01:29:12 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
File: description (1.96 KB, text/plain)
2023-12-27 17:31 UTC, aannoaanno
no flags Details
File: os_info (699 bytes, text/plain)
2023-12-27 17:31 UTC, aannoaanno
no flags Details

Description aannoaanno 2023-12-27 17:31:44 UTC
Description of problem:
SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pressure.

*****  Plugin catchall (100. confidence) suggests   **************************

Wenn Sie denken, dass es mariadbd standardmäßig erlaubt sein sollte, write Zugriff auf memory.pressure file zu erhalten.
Then sie sollten dies als Fehler melden.
Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen.
Do
zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen:
# ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd
# semodule -X 300 -i my-mariadbd.pp

Additional Information:
Source Context                system_u:system_r:mysqld_t:s0
Target Context                system_u:object_r:cgroup_t:s0
Target Objects                memory.pressure [ file ]
Source                        mariadbd
Source Path                   mariadbd
Port                          <Unbekannt>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-39.3-1.fc39.noarch
Local Policy RPM              selinux-policy-targeted-39.3-1.fc39.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.6.8-200.fc39.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Thu Dec 21 04:01:49 UTC 2023
                              x86_64
Alert Count                   9
First Seen                    2023-12-26 12:02:04 CET
Last Seen                     2023-12-27 18:29:29 CET
Local ID                      826f3f56-06b3-416a-917f-8bf68259e820

Raw Audit Messages
type=AVC msg=audit(1703698169.182:144): avc:  denied  { write } for  pid=2521 comm="mariadbd" name="memory.pressure" dev="cgroup2" ino=6338 scontext=system_u:system_r:mysqld_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=0


Hash: mariadbd,mysqld_t,cgroup_t,file,write

Version-Release number of selected component:
selinux-policy-targeted-39.3-1.fc39.noarch

Additional info:
reporter:       libreport-2.17.11
reason:         SELinux is preventing mariadbd from 'write' accesses on the Datei memory.pressure.
package:        selinux-policy-targeted-39.3-1.fc39.noarch
component:      selinux-policy
hashmarkername: setroubleshoot
type:           libreport
kernel:         6.6.8-200.fc39.x86_64
component:      selinux-policy

Comment 1 aannoaanno 2023-12-27 17:31:46 UTC
Created attachment 2006123 [details]
File: description

Comment 2 aannoaanno 2023-12-27 17:31:48 UTC
Created attachment 2006124 [details]
File: os_info

Comment 3 Zdenek Pytela 2024-01-08 08:46:56 UTC
*** Bug 2257049 has been marked as a duplicate of this bug. ***

Comment 4 Zdenek Pytela 2024-02-09 10:03:12 UTC
*** Bug 2256274 has been marked as a duplicate of this bug. ***

Comment 5 Matt Kinni 2024-07-14 23:07:16 UTC
Same error is occurring in Fedora 40:

SELinux is preventing mariadbd from write access on the file memory.pressure.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that mariadbd should be allowed write access on the memory.pressure file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd
# semodule -X 300 -i my-mariadbd.pp

Additional Information:
Source Context                system_u:system_r:mysqld_t:s0
Target Context                system_u:object_r:cgroup_t:s0
Target Objects                memory.pressure [ file ]
Source                        mariadbd
Source Path                   mariadbd
Port                          <Unknown>
Host                          cipix
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-40.23-1.fc40.noarch
Local Policy RPM              mysql-selinux-1.0.10-3.fc40.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     cipix
Platform                      Linux cipix 6.9.5-200.fc40.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Sun Jun 16 15:47:09 UTC 2024
                              x86_64
Alert Count                   8
First Seen                    2024-07-03 23:54:37 MST
Last Seen                     2024-07-14 15:59:17 MST
Local ID                      76778e88-f058-4a74-bbfa-23ea11a5d896

Raw Audit Messages
type=AVC msg=audit(1720997957.815:231): avc:  denied  { write } for  pid=7338 comm="mariadbd" name="memory.pressure" dev="cgroup2" ino=13132 scontext=system_u:system_r:mysqld_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=0


Hash: mariadbd,mysqld_t,cgroup_t,file,write

Comment 6 Timm Fitschen 2024-07-18 13:02:25 UTC
Same problem here.

The suggestion to allow access via

´´´
# ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd
# semodule -X 300 -i my-mariadbd.pp
´´´

didn't really solve the issue. While SELinux is not complaining anymore, MariaDB startup fails with the exact same error as before.

´´´
# systemctl status mariadb
× mariadb.service - MariaDB 10.11 database server
     Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled; preset: disabled)
    Drop-In: /usr/lib/systemd/system/service.d
             └─10-timeout-abort.conf
     Active: failed (Result: exit-code) since Thu 2024-07-18 14:51:17 CEST; 8min ago
       Docs: man:mariadbd(8)
             https://mariadb.com/kb/en/library/systemd/
    Process: 26529 ExecStartPre=/usr/libexec/mariadb-check-socket (code=exited, status=0/SUCCESS)
    Process: 26555 ExecStartPre=/usr/libexec/mariadb-prepare-db-dir mariadb.service (code=exited, status=0/SUCCESS)
    Process: 26591 ExecStart=/usr/libexec/mariadbd --basedir=/usr $MYSQLD_OPTS $_WSREP_NEW_CLUSTER (code=exited, status=1/FAILURE)
   Main PID: 26591 (code=exited, status=1/FAILURE)
     Status: "MariaDB server is down"
        CPU: 161ms


# journalctl -xeu mariadb.service
Jul 18 14:51:16 foras systemd[1]: Starting mariadb.service - MariaDB 10.11 database server...
░░ Subject: A start job for unit mariadb.service has begun execution
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A start job for unit mariadb.service has begun execution.
░░ 
░░ The job identifier is 9176.
Jul 18 14:51:16 foras mariadb-check-socket[26529]: Socket file /var/lib/mysql/mysql.sock exists.
Jul 18 14:51:16 foras mariadb-check-socket[26529]: No process is using /var/lib/mysql/mysql.sock, which means it is a garbage, so it will be removed automatically.
Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: Database MariaDB is probably initialized in /var/lib/mysql already, nothing is done.
Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: If this is not the case, make sure the /var/lib/mysql is empty before running mariadb-prepare-db-dir.
Jul 18 14:51:16 foras (mariadbd)[26591]: mariadb.service: Referenced but unset environment variable evaluates to an empty string: MYSQLD_OPTS, _WSREP_NEW_CLUSTER
Jul 18 14:51:17 foras systemd[1]: mariadb.service: Main process exited, code=exited, status=1/FAILURE
░░ Subject: Unit process exited
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ An ExecStart= process belonging to unit mariadb.service has exited.
░░ 
░░ The process' exit code is 'exited' and its exit status is 1.
Jul 18 14:51:17 foras systemd[1]: mariadb.service: Failed with result 'exit-code'.
░░ Subject: Unit failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ The unit mariadb.service has entered the 'failed' state with result 'exit-code'.
Jul 18 14:51:17 foras systemd[1]: Failed to start mariadb.service - MariaDB 10.11 database server.
░░ Subject: A start job for unit mariadb.service has failed
░░ Defined-By: systemd
░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
░░ 
░░ A start job for unit mariadb.service has finished with a failure.
░░ 
░░ The job identifier is 9176 and the job result is failed.
```

Doesn't this suggest the real problem has something to do with `Referenced but unset environment variable evaluates to an empty string: MYSQLD_OPTS, _WSREP_NEW_CLUSTER`?

Comment 7 Timm Fitschen 2024-07-19 11:51:33 UTC
(In reply to Timm Fitschen from comment #6)
> Same problem here.
> 
> The suggestion to allow access via
> 
> ´´´
> # ausearch -c 'mariadbd' --raw | audit2allow -M my-mariadbd
> # semodule -X 300 -i my-mariadbd.pp
> ´´´
> 
> didn't really solve the issue. While SELinux is not complaining anymore,
> MariaDB startup fails with the exact same error as before.
> 
> ´´´
> # systemctl status mariadb
> × mariadb.service - MariaDB 10.11 database server
>      Loaded: loaded (/usr/lib/systemd/system/mariadb.service; disabled;
> preset: disabled)
>     Drop-In: /usr/lib/systemd/system/service.d
>              └─10-timeout-abort.conf
>      Active: failed (Result: exit-code) since Thu 2024-07-18 14:51:17 CEST;
> 8min ago
>        Docs: man:mariadbd(8)
>              https://mariadb.com/kb/en/library/systemd/
>     Process: 26529 ExecStartPre=/usr/libexec/mariadb-check-socket
> (code=exited, status=0/SUCCESS)
>     Process: 26555 ExecStartPre=/usr/libexec/mariadb-prepare-db-dir
> mariadb.service (code=exited, status=0/SUCCESS)
>     Process: 26591 ExecStart=/usr/libexec/mariadbd --basedir=/usr
> $MYSQLD_OPTS $_WSREP_NEW_CLUSTER (code=exited, status=1/FAILURE)
>    Main PID: 26591 (code=exited, status=1/FAILURE)
>      Status: "MariaDB server is down"
>         CPU: 161ms
> 
> 
> # journalctl -xeu mariadb.service
> Jul 18 14:51:16 foras systemd[1]: Starting mariadb.service - MariaDB 10.11
> database server...
> ░░ Subject: A start job for unit mariadb.service has begun execution
> ░░ Defined-By: systemd
> ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
> ░░ 
> ░░ A start job for unit mariadb.service has begun execution.
> ░░ 
> ░░ The job identifier is 9176.
> Jul 18 14:51:16 foras mariadb-check-socket[26529]: Socket file
> /var/lib/mysql/mysql.sock exists.
> Jul 18 14:51:16 foras mariadb-check-socket[26529]: No process is using
> /var/lib/mysql/mysql.sock, which means it is a garbage, so it will be
> removed automatically.
> Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: Database MariaDB is
> probably initialized in /var/lib/mysql already, nothing is done.
> Jul 18 14:51:16 foras mariadb-prepare-db-dir[26555]: If this is not the
> case, make sure the /var/lib/mysql is empty before running
> mariadb-prepare-db-dir.
> Jul 18 14:51:16 foras (mariadbd)[26591]: mariadb.service: Referenced but
> unset environment variable evaluates to an empty string: MYSQLD_OPTS,
> _WSREP_NEW_CLUSTER
> Jul 18 14:51:17 foras systemd[1]: mariadb.service: Main process exited,
> code=exited, status=1/FAILURE
> ░░ Subject: Unit process exited
> ░░ Defined-By: systemd
> ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
> ░░ 
> ░░ An ExecStart= process belonging to unit mariadb.service has exited.
> ░░ 
> ░░ The process' exit code is 'exited' and its exit status is 1.
> Jul 18 14:51:17 foras systemd[1]: mariadb.service: Failed with result
> 'exit-code'.
> ░░ Subject: Unit failed
> ░░ Defined-By: systemd
> ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
> ░░ 
> ░░ The unit mariadb.service has entered the 'failed' state with result
> 'exit-code'.
> Jul 18 14:51:17 foras systemd[1]: Failed to start mariadb.service - MariaDB
> 10.11 database server.
> ░░ Subject: A start job for unit mariadb.service has failed
> ░░ Defined-By: systemd
> ░░ Support: https://lists.freedesktop.org/mailman/listinfo/systemd-devel
> ░░ 
> ░░ A start job for unit mariadb.service has finished with a failure.
> ░░ 
> ░░ The job identifier is 9176 and the job result is failed.
> ```
> 
> Doesn't this suggest the real problem has something to do with `Referenced
> but unset environment variable evaluates to an empty string: MYSQLD_OPTS,
> _WSREP_NEW_CLUSTER`?

On further investigation, I found that MariaDB wouldn't start because of

```
2024-07-18 14:51:16 0 [ERROR] InnoDB: Upgrade after a crash is not supported. The redo log was created with MariaDB 10.5.16. You must start up and shut down MariaDB 10.7 or earlier.
```

So I did as recommended: downgrade to mariadb-10.5.23, then start and stop mariadb. then update mariadb to 10.11 again. start mariadb-10.11 -- everything worked fine, so I finally disabled the SELinux policy with `semodule -d my-mariadbd`. So I ended up with the following situation: 

1) I am able to start mariadb via systemctl and it is working fine. 
2) But SELinux is complaining again that "SELinux is preventing mariadbd from write access on the file memory.pressure." without further negative implications for now.

I hope this helps.

Comment 8 Fedora Update System 2024-09-16 13:22:53 UTC
FEDORA-2024-3721532bce (mysql-selinux-1.0.11-1.fc40) has been submitted as an update to Fedora 40.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-3721532bce

Comment 9 Fedora Update System 2024-09-16 13:22:55 UTC
FEDORA-2024-28bb0038ce (mysql-selinux-1.0.11-1.fc39) has been submitted as an update to Fedora 39.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-28bb0038ce

Comment 10 Fedora Update System 2024-09-16 13:22:57 UTC
FEDORA-2024-4f35baf4d4 (mysql-selinux-1.0.11-1.fc41) has been submitted as an update to Fedora 41.
https://bodhi.fedoraproject.org/updates/FEDORA-2024-4f35baf4d4

Comment 11 Fedora Update System 2024-09-17 03:07:46 UTC
FEDORA-2024-4f35baf4d4 has been pushed to the Fedora 41 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-4f35baf4d4`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-4f35baf4d4

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Fedora Update System 2024-09-17 03:12:46 UTC
FEDORA-2024-28bb0038ce has been pushed to the Fedora 39 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-28bb0038ce`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-28bb0038ce

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 13 Fedora Update System 2024-09-18 01:42:48 UTC
FEDORA-2024-3721532bce has been pushed to the Fedora 40 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-3721532bce`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-3721532bce

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 14 Fedora Update System 2024-09-25 01:29:12 UTC
FEDORA-2024-4f35baf4d4 (mysql-selinux-1.0.11-1.fc41) has been pushed to the Fedora 41 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 15 Fedora Update System 2024-09-25 02:40:29 UTC
FEDORA-2024-28bb0038ce (mysql-selinux-1.0.11-1.fc39) has been pushed to the Fedora 39 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 16 Fedora Update System 2024-09-26 02:44:13 UTC
FEDORA-2024-3721532bce (mysql-selinux-1.0.11-1.fc40) has been pushed to the Fedora 40 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.