Fedora Account System
Red Hat Associate
Red Hat Customer
I booted the Fedora Rawhide/41 KDE Plasma live image Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso in a QEMU/KVM VM using GNOME Boxes with 3D acceleration enabled using the virgl driver from mesa 24.1.0-rc4. Plasma 6.0.4 on Wayland started. I started Konsole. I installed nautilus with sudo dnf install nautilus. nautilus requires gvfs which requires wsdd. useradd and groupadd were denied writing to /run/systemd/io.systemd.NamespaceResource when creating the wsdd user and group as wsdd was installed as a dependency. May 20 19:35:10 audit[3784]: AVC avc: denied { write } for pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3784]: AVC avc: denied { write } for pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3784]: AVC avc: denied { write } for pid=3784 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3784]: ADD_GROUP pid=3784 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' May 20 19:35:10 groupadd[3784]: group added to /etc/group: name=wsdd, GID=980 May 20 19:35:10 audit[3784]: GRP_MGMT pid=3784 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-shadow-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' May 20 19:35:10 groupadd[3784]: group added to /etc/gshadow: name=wsdd May 20 19:35:10 groupadd[3784]: new group: name=wsdd, GID=980 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 useradd[3789]: new user: name=wsdd, UID=980, GID=980, home=/, shell=/sbin/nologin, from=none May 20 19:35:10 audit[3789]: AVC avc: denied { write } for pid=3789 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=839 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 20 19:35:10 audit[3789]: ADD_USER pid=3789 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 msg='op=add-user acct="wsdd" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' Reproducible: Didn't try Steps to Reproduce: 1. Boot a Fedora 40 KDE Plasma installation updated to 2024-5-20 with updates-testing enabled 2. Log in to Plasma 6.0.4 on Wayland 3. Start Konsole 4. Install GNOME Boxes if it isn't already with sudo dnf install gnome-boxes 5. Download Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso from https://koji.fedoraproject.org/koji/buildinfo?buildID=2453143 6. Start GNOME Boxes 7. Boot Fedora-KDE-Live-x86_64-Rawhide-20240518.n.0.iso in a GNOME Boxes QEMU/KVM VM with 3 GiB RAM, UEFI enabled, and 3D acceleration enabled 8. Start Konsole 9. In Konsole, run sudo dnf install nautilus Actual Results: useradd and groupadd were denied writing to /run/systemd/io.systemd.NamespaceResource when creating the wsdd user and group Expected Results: No denials should have happened.
The denials I reported were with selinux-policy-40.18-3.fc41 and the targeted policy in enforcing mode. The same denials also happened when installing nautilus with selinux-policy-40.20-1.fc41 in Fedora-KDE-Live-x86_64-Rawhide-20240521.n.0.iso https://koji.fedoraproject.org/koji/buildinfo?buildID=2454413 The wsdd preinstall scriptlet had the useradd and groupadd commands which resulted in the denials. rpm -q --scripts wsdd preinstall scriptlet (using /bin/sh): getent group wsdd >/dev/null || groupadd -r wsdd getent passwd wsdd >/dev/null || \ useradd -r -g wsdd -d / -s /sbin/nologin \ -c "Web Services Dynamic Discovery host daemon" wsdd exit 0 When I ran sudo dnf install setroubleshoot in a VM using Fedora-KDE-Live-x86_64-Rawhide-20240521.n.0.iso, the same type of denials happened when the setroubleshoot user and group were created. May 21 13:15:28 audit[3006]: AVC avc: denied { write } for pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:28 audit[3006]: AVC avc: denied { write } for pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:28 audit[3006]: AVC avc: denied { write } for pid=3006 comm="groupadd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:28 audit[3006]: ADD_GROUP pid=3006 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' May 21 13:15:28 groupadd[3006]: group added to /etc/group: name=setroubleshoot, GID=980 May 21 13:15:28 audit[3006]: GRP_MGMT pid=3006 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:groupadd_t:s0-s0:c0.c1023 msg='op=add-shadow-group id=980 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' May 21 13:15:28 groupadd[3006]: group added to /etc/gshadow: name=setroubleshoot May 21 13:15:28 groupadd[3006]: new group: name=setroubleshoot, GID=980 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 useradd[3011]: new user: name=setroubleshoot, UID=980, GID=980, home=/var/lib/setroubleshoot, shell=/usr/sbin/nologin, from=none May 21 13:15:29 audit[3011]: AVC avc: denied { write } for pid=3011 comm="useradd" name="io.systemd.NamespaceResource" dev="tmpfs" ino=836 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0 May 21 13:15:29 audit[3011]: ADD_USER pid=3011 uid=0 auid=1000 ses=2 subj=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 msg='op=add-user acct="setroubleshoot" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' The setroubleshoot-server preinstall scriptlet had the useradd and groupadd commands creating the setroubleshoot user and group. rpm -q --scripts setroubleshoot-server preinstall scriptlet (using /bin/sh): # generated from setroubleshoot.sysusers getent group 'setroubleshoot' >/dev/null || groupadd -r 'setroubleshoot' || : getent passwd 'setroubleshoot' >/dev/null || \ useradd -r -g 'setroubleshoot' -d '/var/lib/setroubleshoot' -s '/usr/sbin/nologin' -c 'SELinux troubleshoot server' 'setroubleshoot' || :
useradd trace (sockfile write): useradd 22124 [059] 45466.585880: avc:selinux_audited: requested=0x4 denied=0x4 audited=0x4 result=-13 scontext=unconfined_u:unconfined_r:useradd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms]) ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms]) ffffffff8979b6db common_lsm_audit+0x2ab ([kernel.kallsyms]) ffffffff897713a3 slow_avc_audit+0xb3 ([kernel.kallsyms]) ffffffff89774e7e audit_inode_permission+0x8e ([kernel.kallsyms]) ffffffff8977ac56 selinux_inode_permission+0x196 ([kernel.kallsyms]) ffffffff8976b33b security_inode_permission+0x3b ([kernel.kallsyms]) ffffffff89fa4773 unix_find_other+0x173 ([kernel.kallsyms]) ffffffff89fa66e3 unix_stream_connect+0xe3 ([kernel.kallsyms]) ffffffff89df0a3b __sys_connect+0xab ([kernel.kallsyms]) ffffffff89df0a88 __x64_sys_connect+0x18 ([kernel.kallsyms]) ffffffff8a17f4b2 do_syscall_64+0x82 ([kernel.kallsyms]) ffffffff8a20012f entry_SYSCALL_64_after_hwframe+0x76 ([kernel.kallsyms]) 7f4f3003b104 __libc_connect+0x14 (/usr/lib64/libc.so.6) 7f4f2f9d0175 userdb_connect+0x245 (/usr/lib64/libnss_systemd.so.2) 7f4f2f9d1b42 userdb_start_query+0x392 (inlined) 7f4f2f9d21c3 groupdb_by_name+0xf3 (/usr/lib64/libnss_systemd.so.2) 7f4f2f9adebf _nss_systemd_getgrnam_r+0x29f (/usr/lib64/libnss_systemd.so.2) 7f4f300610a7 getgrnam_r@@GLIBC_2.2.5+0x127 (/usr/lib64/libc.so.6) 5558e802f1d5 [unknown] (/usr/sbin/useradd) 5558e803026a [unknown] (/usr/sbin/useradd) 5558e8027f06 [unknown] (/usr/sbin/useradd) 7f4f2ff4b1c7 __libc_start_call_main+0x77 (/usr/lib64/libc.so.6) 7f4f2ff4b28a __libc_start_main@@GLIBC_2.34+0x8a (/usr/lib64/libc.so.6) 5558e802a704 [unknown] (/usr/sbin/useradd) auditd trace (connectto): auditd 1456 [062] 45466.525185: avc:selinux_audited: requested=0x200000 denied=0x200000 audited=0x200000 result=-13 scontext=system_u:system_r:auditd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms]) ffffffff897700b6 avc_audit_post_callback+0x216 ([kernel.kallsyms]) ffffffff8979b6db common_lsm_audit+0x2ab ([kernel.kallsyms]) ffffffff897713a3 slow_avc_audit+0xb3 ([kernel.kallsyms]) ffffffff89771c5f avc_has_perm+0xbf ([kernel.kallsyms]) ffffffff897747e7 selinux_socket_unix_stream_connect+0x87 ([kernel.kallsyms]) ffffffff8976858d security_unix_stream_connect+0x3d ([kernel.kallsyms]) ffffffff89fa69eb unix_stream_connect+0x3eb ([kernel.kallsyms]) ffffffff89df0a3b __sys_connect+0xab ([kernel.kallsyms]) ffffffff89df0a88 __x64_sys_connect+0x18 ([kernel.kallsyms]) ffffffff8a17f4b2 do_syscall_64+0x82 ([kernel.kallsyms]) ffffffff8a20012f entry_SYSCALL_64_after_hwframe+0x76 ([kernel.kallsyms]) 7f2152ab113b __libc_connect+0x4b (/usr/lib64/libc.so.6) 7f2152330175 userdb_connect+0x245 (/usr/lib64/libnss_systemd.so.2) 7f2152331b42 userdb_start_query+0x392 (inlined) 7f2152305b97 _nss_systemd_getgrgid_r+0x447 (/usr/lib64/libnss_systemd.so.2) 7f2152ad6ba6 getgrgid_r@@GLIBC_2.2.5+0x126 (/usr/lib64/libc.so.6) 7f2152ad69af getgrgid+0x9f (/usr/lib64/libc.so.6) 7f2152ca67d7 [unknown] (/usr/lib64/libauparse.so.0.0.0) 7f2152cab1b4 auparse_do_interpretation+0x6c4 (/usr/lib64/libauparse.so.0.0.0) 7f2152cae50b [unknown] (/usr/lib64/libauparse.so.0.0.0) 561aba120585 [unknown] (/usr/sbin/auditd) 561aba120801 [unknown] (/usr/sbin/auditd) 561aba122f46 [unknown] (/usr/sbin/auditd) 561aba1237c9 [unknown] (/usr/sbin/auditd)
*** Bug 2290722 has been marked as a duplicate of this bug. ***
*** Bug 2290694 has been marked as a duplicate of this bug. ***
We see that in our Cockpit tests, too, e.g. in https://artifacts.dev.testing-farm.io/d74fd607-89b0-4904-a51c-c14a0069b0c0/ Direct journal link: https://artifacts.dev.testing-farm.io/d74fd607-89b0-4904-a51c-c14a0069b0c0/work-mainu4ncndch/plans/all/main/execute/data/guest/default-0/test/browser/main-1/data/TestJournal-testAbrtSegv-fedora-41-10.88.0.1-22-FAIL.log.gz For us this breaks ABRT: AVC avc: denied { write } for pid=915 comm="abrt-dump-journ" name="io.systemd.NamespaceResource" dev="tmpfs" ino=827 scontext=system_u:system_r:abrt_dump_oops_t:s0 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file permissive=0
> For us this breaks ABRT: Correction -- ABRT is broken even with `setenforce 1` (and no logs), I'll report that separately.
*** This bug has been marked as a duplicate of bug 2290477 ***