Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing /usr/bin/abrt-dump-journal-core from 'connectto' accesses on the unix_stream_socket /run/systemd/userdb/io.systemd.Home. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that abrt-dump-journal-core should be allowed connectto access on the io.systemd.Home unix_stream_socket by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'abrt-dump-journ' --raw | audit2allow -M my-abrtdumpjourn # semodule -X 300 -i my-abrtdumpjourn.pp Additional Information: Source Context system_u:system_r:abrt_dump_oops_t:s0 Target Context system_u:system_r:init_t:s0 Target Objects /run/systemd/userdb/io.systemd.Home [ unix_stream_socket ] Source abrt-dump-journ Source Path /usr/bin/abrt-dump-journal-core Port <Unknown> Host (removed) Source RPM Packages abrt-addon-ccpp-2.17.5-1.fc41.x86_64 Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.13-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.13-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Permissive Host Name (removed) Platform Linux (removed) 6.8.0- 0.rc5.20240222git39133352cbed.44.fc41.x86_64+debug #1 SMP PREEMPT_DYNAMIC Fri Feb 23 01:27:39 +05 2024 x86_64 Alert Count 29 First Seen 2024-02-25 16:49:41 +05 Last Seen 2024-02-25 23:47:32 +05 Local ID ff1e90aa-6d35-4314-86a5-8437b8a564c0 Raw Audit Messages type=AVC msg=audit(1708886852.210:1500): avc: denied { connectto } for pid=1503 comm="abrt-dump-journ" path="/run/systemd/userdb/io.systemd.Home" scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=1 type=SYSCALL msg=audit(1708886852.210:1500): arch=x86_64 syscall=connect success=yes exit=0 a0=3b a1=7fffd87b9910 a2=26 a3=559c79839a70 items=1 ppid=1 pid=1503 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm=abrt-dump-journ exe=/usr/bin/abrt-dump-journal-core subj=system_u:system_r:abrt_dump_oops_t:s0 key=(null) type=CWD msg=audit(1708886852.210:1500): cwd=/ type=PATH msg=audit(1708886852.210:1500): item=0 name=/run/systemd/userdb/io.systemd.Home inode=2190 dev=00:1a mode=0140666 ouid=0 ogid=0 rdev=00:00 obj=system_u:object_r:systemd_userdbd_runtime_t:s0 nametype=NORMAL cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0 Hash: abrt-dump-journ,abrt_dump_oops_t,init_t,unix_stream_socket,connectto Version-Release number of selected component: selinux-policy-targeted-40.13-1.fc40.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing /usr/bin/abrt-dump-journal-core from 'connectto' accesses on the unix_stream_socket /run/systemd/userdb/io.systemd.Home. package: selinux-policy-targeted-40.13-1.fc40.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.8.0-0.rc5.20240222git39133352cbed.44.fc41.x86_64+debug component: selinux-policy
Created attachment 2018758 [details] File: description
Created attachment 2018759 [details] File: os_info
*** This bug has been marked as a duplicate of bug 2265927 ***
Still occurring with selinux-policy-targeted-40.17-1.fc40: SELinux is preventing abrt-dump-journ from 'connectto' accesses on the unix_stream_socket /run/systemd/userdb/io.systemd.Home. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that abrt-dump-journ should be allowed connectto access on the io.systemd.Home unix_stream_socket by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'abrt-dump-journ' --raw | audit2allow -M my-abrtdumpjourn # semodule -X 300 -i my-abrtdumpjourn.pp Additional Information: Source Context system_u:system_r:abrt_dump_oops_t:s0 Target Context system_u:system_r:init_t:s0 Target Objects /run/systemd/userdb/io.systemd.Home [ unix_stream_socket ] Source abrt-dump-journ Source Path abrt-dump-journ Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.17-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.17-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.8.7-300.fc40.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Apr 17 19:21:08 UTC 2024 x86_64 Alert Count 4 First Seen 2024-04-27 10:12:16 PDT Last Seen 2024-04-27 10:12:17 PDT Local ID 1f78b0d6-7b60-4f44-ae9b-55a80ff66f66 Raw Audit Messages type=AVC msg=audit(1714237937.437:208): avc: denied { connectto } for pid=785 comm="abrt-dump-journ" path="/run/systemd/userdb/io.systemd.Home" scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=0 Hash: abrt-dump-journ,abrt_dump_oops_t,init_t,unix_stream_socket,connectto
Reopening, this one is abrt->sd-homed IPC.
(In reply to Zdenek Pytela from comment #5) > Reopening, this one is abrt->sd-homed IPC. Thanks, Zdenek.
*** Bug 2278438 has been marked as a duplicate of this bug. ***
*** Bug 2278643 has been marked as a duplicate of this bug. ***
*** Bug 2279040 has been marked as a duplicate of this bug. ***
*** Bug 2279106 has been marked as a duplicate of this bug. ***
*** Bug 2279238 has been marked as a duplicate of this bug. ***
FEDORA-2024-759c80369d (selinux-policy-40.18-2.fc40) has been submitted as an update to Fedora 40. https://bodhi.fedoraproject.org/updates/FEDORA-2024-759c80369d
FEDORA-2024-759c80369d has been pushed to the Fedora 40 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2024-759c80369d` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2024-759c80369d See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2024-759c80369d (selinux-policy-40.18-2.fc40) has been pushed to the Fedora 40 stable repository. If problem still persists, please make note of it in this bug report.