Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: SELinux is preventing abrt-dump-journ from 'write' accesses on the sock_file io.systemd.Machine. ***** Plugin catchall (100. confidence) suggests ************************** Si vous pensez que abrt-dump-journ devrait être autorisé à accéder write sur io.systemd.Machine sock_file par défaut. Then vous devriez rapporter ceci en tant qu'anomalie. Vous pouvez générer un module de stratégie local pour autoriser cet accès. Do autoriser cet accès pour le moment en exécutant : # ausearch -c "abrt-dump-journ" --raw | audit2allow -M my-abrtdumpjourn # semodule -X 300 -i my-abrtdumpjourn.pp Additional Information: Source Context system_u:system_r:abrt_dump_oops_t:s0 Target Context system_u:object_r:systemd_userdbd_runtime_t:s0 Target Objects io.systemd.Machine [ sock_file ] Source abrt-dump-journ Source Path abrt-dump-journ Port <Inconnu> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.15-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.8.0-63.fc40.1.x86_64 #1 SMP PREEMPT_DYNAMIC Tue Mar 12 20:12:53 UTC 2024 x86_64 Alert Count 12 First Seen 2024-03-21 10:56:16 CET Last Seen 2024-03-21 10:56:17 CET Local ID d0a59111-2800-4c59-be36-d51e7b270f7d Raw Audit Messages type=AVC msg=audit(1711014977.928:483): avc: denied { write } for pid=4997 comm="abrt-dump-journ" name="io.systemd.Machine" dev="tmpfs" ino=3170 scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0 Hash: abrt-dump-journ,abrt_dump_oops_t,systemd_userdbd_runtime_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-40.15-1.fc40.noarch Additional info: reporter: libreport-2.17.15 reason: SELinux is preventing abrt-dump-journ from 'write' accesses on the sock_file io.systemd.Machine. package: selinux-policy-targeted-40.15-1.fc40.noarch component: selinux-policy hashmarkername: setroubleshoot type: libreport kernel: 6.8.0-63.fc40.1.x86_64 component: selinux-policy
Created attachment 2022892 [details] File: description
Created attachment 2022893 [details] File: os_info
*** This bug has been marked as a duplicate of bug 2265927 ***