Fedora Account System
Red Hat Associate
Red Hat Customer
The logwatch service does NOT complain even if the denials appear. Tested with the following packages: logwatch-7.10-1.fc40.noarch selinux-policy-40.15-1.fc41.noarch selinux-policy-targeted-40.15-1.fc41.noarch sendmail-8.18.1-1.fc40.x86_64 Reproducible: Always Steps to Reproduce: 1. get a Fedora rawhide machine (the targeted policy is active) 2. install the logwatch and sendmail packages 3. start the logwatch service 4. search for SELinux denials Actual Results: ---- type=PROCTITLE msg=audit(03/20/2024 10:36:55.005:657) : proctitle=uptime type=PATH msg=audit(03/20/2024 10:36:55.005:657) : item=0 name=/run/systemd/sessions/ inode=81 dev=00:1a mode=dir,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:systemd_logind_sessions_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(03/20/2024 10:36:55.005:657) : cwd=/ type=SYSCALL msg=audit(03/20/2024 10:36:55.005:657) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x7f18e19bb970 a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2011 pid=2012 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=uptime exe=/usr/bin/uptime subj=system_u:system_r:logwatch_t:s0 key=(null) type=AVC msg=audit(03/20/2024 10:36:55.005:657) : avc: denied { read } for pid=2012 comm=uptime name=sessions dev="tmpfs" ino=81 scontext=system_u:system_r:logwatch_t:s0 tcontext=system_u:object_r:systemd_logind_sessions_t:s0 tclass=dir permissive=0 ---- Expected Results: no SELinux denials
The following SELinux denials appear in permissive mode: ---- type=PROCTITLE msg=audit(03/20/2024 10:46:33.856:662) : proctitle=/usr/sbin/sendmail -t type=SYSCALL msg=audit(03/20/2024 10:46:33.856:662) : arch=x86_64 syscall=fstat success=yes exit=0 a0=0x1 a1=0x7fff244cd710 a2=0x100 a3=0x7fff244cd7b0 items=0 ppid=2047 pid=2063 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=smmsp sgid=smmsp fsgid=smmsp tty=(none) ses=unset comm=sendmail exe=/usr/sbin/sendmail.sendmail subj=system_u:system_r:logwatch_mail_t:s0 key=(null) type=AVC msg=audit(03/20/2024 10:46:33.856:662) : avc: denied { getattr } for pid=2063 comm=sendmail path=socket:[16166] dev="sockfs" ino=16166 scontext=system_u:system_r:logwatch_mail_t:s0 tcontext=system_u:system_r:init_t:s0 tclass=unix_stream_socket permissive=1 ---- type=PROCTITLE msg=audit(03/20/2024 10:46:33.948:663) : proctitle=uptime type=PATH msg=audit(03/20/2024 10:46:33.948:663) : item=0 name=/run/systemd/sessions/ inode=81 dev=00:1a mode=dir,755 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:systemd_logind_sessions_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(03/20/2024 10:46:33.948:663) : cwd=/ type=SYSCALL msg=audit(03/20/2024 10:46:33.948:663) : arch=x86_64 syscall=openat success=yes exit=3 a0=AT_FDCWD a1=0x7f924b1c6970 a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2067 pid=2068 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=uptime exe=/usr/bin/uptime subj=system_u:system_r:logwatch_t:s0 key=(null) type=AVC msg=audit(03/20/2024 10:46:33.948:663) : avc: denied { read } for pid=2068 comm=uptime name=sessions dev="tmpfs" ino=81 scontext=system_u:system_r:logwatch_t:s0 tcontext=system_u:object_r:systemd_logind_sessions_t:s0 tclass=dir permissive=1 ----
Test coverage for this bug exists in a form of PR: * https://src.fedoraproject.org/tests/selinux/pull-request/482 The PR waits for a review.
*** Bug 2274959 has been marked as a duplicate of this bug. ***