Bug 2282040 - useradd and groupadd were denied writing to /run/systemd/io.systemd.NamespaceResource when creating the wsdd user and group
Summary: useradd and groupadd were denied writing to /run/systemd/io.systemd.Namespace...
Keywords:
Status: CLOSED DUPLICATE of bug 2290477
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: Unspecified
OS: Linux
high
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: CockpitTest
: 2290694 2290722 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-05-21 00:39 UTC by Matt Fagnani
Modified: 2024-06-17 15:36 UTC (History)
10 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-06-17 15:36:03 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Matt Fagnani 2024-05-21 00:39:10 UTC
I booted the Fedora Rawhide/41 KDE Plasma live image Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso in a QEMU/KVM VM using GNOME Boxes with 3D acceleration enabled using the virgl driver from mesa 24.1.0-rc4. Plasma 6.0.4 on Wayland started. I started Konsole. I installed nautilus with sudo dnf install nautilus. nautilus requires gvfs which requires wsdd. useradd and groupadd were denied writing to /run/systemd/io.systemd.NamespaceResource when creating the wsdd user and group as wsdd was installed as a dependency.

May 20 19:35:10 audit[3784]: AVC avc:  denied  { write } for  pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3784]: AVC avc:  denied  { write } for  pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3784]: AVC avc:  denied  { write } for  pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3784]: ADD_GROUP pid=3784 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success'
May 20 19:35:10 groupadd[3784]: group added to /etc/group: name=wsdd, GID=980
May 20 19:35:10 audit[3784]: GRP_MGMT pid=3784 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-shadow-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success'
May 20 19:35:10 groupadd[3784]: group added to /etc/gshadow: name=wsdd
May 20 19:35:10 groupadd[3784]: new group: name=wsdd, GID=980
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 useradd[3789]: new user: name=wsdd, UID=980, GID=980, home=/, shell=/sbin/nologin, from=none
May 20 19:35:10 audit[3789]: AVC avc:  denied  { write } for  pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 20 19:35:10 audit[3789]: ADD_USER pid=3789 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 msg='op=add-user acct="wsdd" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success'


Reproducible: Didn't try

Steps to Reproduce:
1. Boot a Fedora 40 KDE Plasma installation updated to 2024-5-20 with updates-testing enabled
2. Log in to Plasma 6.0.4 on Wayland
3. Start Konsole
4. Install GNOME Boxes if it isn't already with sudo dnf install gnome-boxes
5. Download Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso from https://koji.fedoraproject.org/koji/buildinfo?buildID=2453143 
6. Start GNOME Boxes
7. Boot Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso in a GNOME Boxes QEMU/KVM VM with 3 GiB RAM, UEFI enabled, and 3D acceleration enabled
8. Start Konsole
9. In Konsole, run sudo dnf install nautilus
Actual Results:  
useradd and groupadd were denied writing to /run/systemd/io.systemd.NamespaceResource when creating the wsdd user and group 

Expected Results:  
No denials should have happened.

Comment 1 Matt Fagnani 2024-05-21 17:36:38 UTC
The denials I reported were with selinux-policy-40.18-3.fc41 and the targeted policy in enforcing mode. The same denials also happened when installing nautilus with selinux-policy-40.20-1.fc41 in Fedora-KDE-Live-x86_64-Rawhide-20240521.n.0.iso https://koji.fedoraproject.org/koji/buildinfo?buildID=2454413 The wsdd preinstall scriptlet had the useradd and groupadd commands which resulted in the denials.

rpm -q --scripts wsdd
preinstall scriptlet (using /bin/sh):
getent group wsdd >/dev/null || groupadd -r wsdd
getent passwd wsdd >/dev/null || \
    useradd -r -g wsdd -d / -s /sbin/nologin \
    -c "Web Services Dynamic Discovery host daemon" wsdd
exit 0

When I ran sudo dnf install setroubleshoot in a VM using Fedora-KDE-Live-x86_64-Rawhide-20240521.n.0.iso, the same type of denials happened when the setroubleshoot user and group were created. 

May 21 13:15:28 audit[3006]: AVC avc:  denied  { write } for  pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:28 audit[3006]: AVC avc:  denied  { write } for  pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:28 audit[3006]: AVC avc:  denied  { write } for  pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:28 audit[3006]: ADD_GROUP pid=3006 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success'
May 21 13:15:28 groupadd[3006]: group added to /etc/group: name=setroubleshoot, GID=980
May 21 13:15:28 audit[3006]: GRP_MGMT pid=3006 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-shadow-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success'
May 21 13:15:28 groupadd[3006]: group added to /etc/gshadow: name=setroubleshoot
May 21 13:15:28 groupadd[3006]: new group: name=setroubleshoot, GID=980
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 useradd[3011]: new user: name=setroubleshoot, UID=980, GID=980, home=/var/lib/setroubleshoot, shell=/usr/sbin/nologin, from=none
May 21 13:15:29 audit[3011]: AVC avc:  denied  { write } for  pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
May 21 13:15:29 audit[3011]: ADD_USER pid=3011 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 msg='op=add-user acct="setroubleshoot" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success'

The setroubleshoot-server preinstall scriptlet had the useradd and groupadd commands creating the setroubleshoot user and group.
rpm -q --scripts setroubleshoot-server
preinstall scriptlet (using /bin/sh):

# generated from setroubleshoot.sysusers
getent group 'setroubleshoot' >/dev/null || groupadd -r 'setroubleshoot' || :
getent passwd 'setroubleshoot' >/dev/null || \
    useradd -r -g 'setroubleshoot' -d '/var/lib/setroubleshoot' -s '/usr/sbin/nologin' -c 'SELinux troubleshoot server' 'setroubleshoot' || :

Comment 2 Zdenek Pytela 2024-06-05 10:16:18 UTC
useradd trace (sockfile write):

useradd   22124 [059] 45466.585880: avc:selinux_audited: requested=0x4 denied=0x4 audited=0x4 result=-13 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file
        ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms])
        ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms])
        ffffffff8979b6db common_lsm_audit+0x2ab ([kernel.kallsyms])
        ffffffff897713a3 slow_avc_audit+0xb3 ([kernel.kallsyms])
        ffffffff89774e7e audit_inode_permission+0x8e ([kernel.kallsyms])
        ffffffff8977ac56 selinux_inode_permission+0x196 ([kernel.kallsyms])
        ffffffff8976b33b security_inode_permission+0x3b ([kernel.kallsyms])
        ffffffff89fa4773 unix_find_other+0x173 ([kernel.kallsyms])
        ffffffff89fa66e3 unix_stream_connect+0xe3 ([kernel.kallsyms])
        ffffffff89df0a3b __sys_connect+0xab ([kernel.kallsyms])
        ffffffff89df0a88 __x64_sys_connect+0x18 ([kernel.kallsyms])
        ffffffff8a17f4b2 do_syscall_64+0x82 ([kernel.kallsyms])
        ffffffff8a20012f entry_SYSCALL_64_after_hwframe+0x76 ([kernel.kallsyms])
            7f4f3003b104 __libc_connect+0x14 (/usr/lib64/libc.so.6)
            7f4f2f9d0175 userdb_connect+0x245 (/usr/lib64/libnss_systemd.so.2)
            7f4f2f9d1b42 userdb_start_query+0x392 (inlined)
            7f4f2f9d21c3 groupdb_by_name+0xf3 (/usr/lib64/libnss_systemd.so.2)
            7f4f2f9adebf _nss_systemd_getgrnam_r+0x29f (/usr/lib64/libnss_systemd.so.2)
            7f4f300610a7 getgrnam_r@@GLIBC_2.2.5+0x127 (/usr/lib64/libc.so.6)
            5558e802f1d5 [unknown] (/usr/sbin/useradd)
            5558e803026a [unknown] (/usr/sbin/useradd)
            5558e8027f06 [unknown] (/usr/sbin/useradd)
            7f4f2ff4b1c7 __libc_start_call_main+0x77 (/usr/lib64/libc.so.6)
            7f4f2ff4b28a __libc_start_main@@GLIBC_2.34+0x8a (/usr/lib64/libc.so.6)
            5558e802a704 [unknown] (/usr/sbin/useradd)

auditd trace (connectto):

auditd    1456 [062] 45466.525185: avc:selinux_audited: requested=0x200000 denied=0x200000 audited=0x200000 result=-13 scontext=system_u:system_r:auditd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket
        ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms])
        ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms])
        ffffffff8979b6db common_lsm_audit+0x2ab ([kernel.kallsyms])
        ffffffff897713a3 slow_avc_audit+0xb3 ([kernel.kallsyms])
        ffffffff89771c5f avc_has_perm+0xbf ([kernel.kallsyms])
        ffffffff897747e7 selinux_socket_unix_stream_connect+0x87 ([kernel.kallsyms])
        ffffffff8976858d security_unix_stream_connect+0x3d ([kernel.kallsyms])
        ffffffff89fa69eb unix_stream_connect+0x3eb ([kernel.kallsyms])
        ffffffff89df0a3b __sys_connect+0xab ([kernel.kallsyms])
        ffffffff89df0a88 __x64_sys_connect+0x18 ([kernel.kallsyms])
        ffffffff8a17f4b2 do_syscall_64+0x82 ([kernel.kallsyms])
        ffffffff8a20012f entry_SYSCALL_64_after_hwframe+0x76 ([kernel.kallsyms])
            7f2152ab113b __libc_connect+0x4b (/usr/lib64/libc.so.6)
            7f2152330175 userdb_connect+0x245 (/usr/lib64/libnss_systemd.so.2)
            7f2152331b42 userdb_start_query+0x392 (inlined)
            7f2152305b97 _nss_systemd_getgrgid_r+0x447 (/usr/lib64/libnss_systemd.so.2)
            7f2152ad6ba6 getgrgid_r@@GLIBC_2.2.5+0x126 (/usr/lib64/libc.so.6)
            7f2152ad69af getgrgid+0x9f (/usr/lib64/libc.so.6)
            7f2152ca67d7 [unknown] (/usr/lib64/libauparse.so.0.0.0)
            7f2152cab1b4 auparse_do_interpretation+0x6c4 (/usr/lib64/libauparse.so.0.0.0)
            7f2152cae50b [unknown] (/usr/lib64/libauparse.so.0.0.0)
            561aba120585 [unknown] (/usr/sbin/auditd)
            561aba120801 [unknown] (/usr/sbin/auditd)
            561aba122f46 [unknown] (/usr/sbin/auditd)
            561aba1237c9 [unknown] (/usr/sbin/auditd)

Comment 3 Martin Pitt 2024-06-07 09:26:58 UTC
*** Bug 2290722 has been marked as a duplicate of this bug. ***

Comment 4 Martin Pitt 2024-06-07 09:27:03 UTC
*** Bug 2290694 has been marked as a duplicate of this bug. ***

Comment 5 Martin Pitt 2024-06-07 09:28:39 UTC
We see that in our Cockpit tests, too, e.g. in https://artifacts.dev.testing-farm.io/d74fd607-89b0-4904-a51c-c14a0069b0c0/

Direct journal link: https://artifacts.dev.testing-farm.io/d74fd607-89b0-4904-a51c-c14a0069b0c0/work-mainu4ncndch/plans/all/main/execute/data/guest/default-0/test/browser/main-1/data/TestJournal-testAbrtSegv-fedora-41-10.88.0.1-22-FAIL.log.gz

For us this breaks ABRT:

AVC avc:  denied  { write } for  pid=915 comm="abrt-dump-journ" name="io.systemd.NamespaceResource" dev="tmpfs" ino=827 scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0

Comment 6 Martin Pitt 2024-06-07 09:31:18 UTC
> For us this breaks ABRT:

Correction -- ABRT is broken even with `setenforce 1` (and no logs), I'll report that separately.

Comment 7 Zdenek Pytela 2024-06-17 15:36:03 UTC

*** This bug has been marked as a duplicate of bug 2290477 ***


Note You need to log in before you can comment on or make changes to this bug.