Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: After Fedora 40 upgrade SELinux is preventing abrt-dump-journ from 'write' accesses on the sock_file io.systemd.Machine. ***** Plugin catchall (100. confidence) suggests ************************** Si vous pensez que abrt-dump-journ devrait être autorisé à accéder write sur io.systemd.Machine sock_file par défaut. Then vous devriez rapporter ceci en tant qu'anomalie. Vous pouvez générer un module de stratégie local pour autoriser cet accès. Do autoriser cet accès pour le moment en exécutant : # ausearch -c "abrt-dump-journ" --raw | audit2allow -M my-abrtdumpjourn # semodule -X 300 -i my-abrtdumpjourn.pp Additional Information: Source Context system_u:system_r:abrt_dump_oops_t:s0 Target Context system_u:object_r:systemd_userdbd_runtime_t:s0 Target Objects io.systemd.Machine [ sock_file ] Source abrt-dump-journ Source Path abrt-dump-journ Port <Inconnu> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-40.16-1.fc40.noarch Local Policy RPM selinux-policy-targeted-40.16-1.fc40.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.8.7-300.fc40.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Apr 17 19:21:08 UTC 2024 x86_64 Alert Count 1116 First Seen 2024-04-26 19:16:55 CEST Last Seen 2024-04-28 16:17:51 CEST Local ID 48653238-ccd9-42a0-81cb-df62005dfab6 Raw Audit Messages type=AVC msg=audit(1714313871.95:3710): avc: denied { write } for pid=2303 comm="abrt-dump-journ" name="io.systemd.Machine" dev="tmpfs" ino=2462 scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0 tclass=sock_file permissive=0 Hash: abrt-dump-journ,abrt_dump_oops_t,systemd_userdbd_runtime_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-40.16-1.fc40.noarch Additional info: reporter: libreport-2.17.15 hashmarkername: setroubleshoot comment: After Fedora 40 upgrade reason: SELinux is preventing abrt-dump-journ from 'write' accesses on the sock_file io.systemd.Machine. package: selinux-policy-targeted-40.16-1.fc40.noarch kernel: 6.8.7-300.fc40.x86_64 type: libreport component: selinux-policy component: selinux-policy
Created attachment 2029781 [details] File: os_info
Created attachment 2029782 [details] File: description
*** This bug has been marked as a duplicate of bug 2265927 ***