Bug 2270484 - SELinux denials appear during (re)start of the logwatch service
Summary: SELinux denials appear during (re)start of the logwatch service
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: x86_64
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 2274959 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-03-20 14:45 UTC by Milos Malik
Modified: 2024-04-15 05:58 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-04-14 20:57:47 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2070 0 None Merged Allow logwatch read logind sessions files 2024-03-21 19:25:56 UTC

Description Milos Malik 2024-03-20 14:45:58 UTC
The logwatch service does NOT complain even if the denials appear.

Tested with the following packages:

logwatch-7.10-1.fc40.noarch
selinux-policy-40.15-1.fc41.noarch
selinux-policy-targeted-40.15-1.fc41.noarch
sendmail-8.18.1-1.fc40.x86_64


Reproducible: Always

Steps to Reproduce:
1. get a Fedora rawhide machine (the targeted policy is active)
2. install the logwatch and sendmail packages
3. start the logwatch service
4. search for SELinux denials

Actual Results:  
----
type=PROCTITLE msg=audit(03/20/2024 10:36:55.005:657) : proctitle=uptime 
type=PATH msg=audit(03/20/2024 10:36:55.005:657) : item=0 name=/run/systemd/sessions/ inode=81 dev=00:1a mode=dir,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:systemd_logind_sessions_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(03/20/2024 10:36:55.005:657) : cwd=/ 
type=SYSCALL msg=audit(03/20/2024 10:36:55.005:657) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x7f18e19bb970 a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2011 pid=2012 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=uptime exe=/usr/bin/uptime subj=system_u:system_r:logwatch_t:s0 key=(null) 
type=AVC msg=audit(03/20/2024 10:36:55.005:657) : avc:  denied  { read } for  pid=2012 comm=uptime name=sessions dev="tmpfs" ino=81 scontext=system_u:system_r:logwatch_t:s0 tcontext=system_u:object_r:systemd_logind_sessions_t:s0 tclass=dir permissive=0 
----

Expected Results:  
no SELinux denials

Comment 1 Milos Malik 2024-03-20 14:47:52 UTC
The following SELinux denials appear in permissive mode:
----
type=PROCTITLE msg=audit(03/20/2024 10:46:33.856:662) : proctitle=/usr/sbin/sendmail -t 
type=SYSCALL msg=audit(03/20/2024 10:46:33.856:662) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0x1 a1=0x7fff244cd710 a2=0x100 a3=0x7fff244cd7b0 items=0 ppid=2047 pid=2063 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=smmsp sgid=smmsp fsgid=smmsp tty=(none) ses=unset comm=sendmail exe=/usr/sbin/sendmail.sendmail subj=system_u:system_r:logwatch_mail_t:s0 key=(null) 
type=AVC msg=audit(03/20/2024 10:46:33.856:662) : avc:  denied  { getattr } for  pid=2063 comm=sendmail path=socket:[16166] dev="sockfs" ino=16166 scontext=system_u:system_r:logwatch_mail_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=1 
----
type=PROCTITLE msg=audit(03/20/2024 10:46:33.948:663) : proctitle=uptime 
type=PATH msg=audit(03/20/2024 10:46:33.948:663) : item=0 name=/run/systemd/sessions/ inode=81 dev=00:1a mode=dir,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:systemd_logind_sessions_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(03/20/2024 10:46:33.948:663) : cwd=/ 
type=SYSCALL msg=audit(03/20/2024 10:46:33.948:663) : arch=x86_64 syscall=openat success=yes exit=3 a0=AT_FDCWD a1=0x7f924b1c6970 a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2067 pid=2068 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=uptime exe=/usr/bin/uptime subj=system_u:system_r:logwatch_t:s0 key=(null) 
type=AVC msg=audit(03/20/2024 10:46:33.948:663) : avc:  denied  { read } for  pid=2068 comm=uptime name=sessions dev="tmpfs" ino=81 scontext=system_u:system_r:logwatch_t:s0 tcontext=system_u:object_r:systemd_logind_sessions_t:s0 tclass=dir permissive=1 
----

Comment 2 Milos Malik 2024-03-20 20:29:13 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/482

The PR waits for a review.

Comment 3 Zdenek Pytela 2024-04-15 05:58:28 UTC
*** Bug 2274959 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.