Fedora Account System
Red Hat Associate
Red Hat Customer
I booted the Fedora Rawhide KDE live image Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso in a QEMU/KVM VM in GNOME Boxes in a Fedora 40 KDE host. There were many denials involving systemd-nsresourced with selinux-policy-41.1-1.fc41 during boot and after. systemd-nsresourced was denied writing to /sys/fs/cgroup/system.slice/systemd-nsresourced.service/memory.pressure when it started. Jun 04 16:42:35 systemd[1]: Starting systemd-nsresourced.service - Namespace Resource Manager... Jun 04 16:42:35 systemd[1]: Starting systemd-userdbd.service - User Database Manager... Jun 04 16:42:35 systemd[1]: Finished systemd-random-seed.service - Load/Save OS Random Seed. Jun 04 16:42:35 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices. Jun 04 16:42:35 systemd[1]: Finished systemd-journal-flush.service - Flush Journal to Persistent Storage. Jun 04 16:42:35 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-journal-flush comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jun 04 16:42:35 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables. Jun 04 16:42:35 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jun 04 16:42:35 audit[1060]: AVC avc: denied { write } for pid=1060 comm="systemd-nsresou" name="memory.pressure" dev="cgroup2" ino=2686 scontext=system_u:system_r:systemd_nsresourced_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=1 Jun 04 16:42:35 audit[1060]: SYSCALL arch=c000003e syscall=257 success=yes exit=8 a0=ffffff9c a1=7ffd660cde90 a2=80902 a3=0 items=0 ppid=1 pid=1060 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-nsresou" exe="/usr/lib/systemd/systemd-nsresourced" subj=system_u:system_r:systemd_nsresourced_t:s0 key=(null) systemd-oomd, systemd-resolved, polkitd, accounts-daemon, sddm-helper, the systemd user daemons run by user and user, auditd, pkla-check-authorization, cupsd, and systemd-stdio-bridge were denied connecting to /run/systemd/io.systemd.NamespaceResource Jun 04 16:42:39 systemd[1]: Starting systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer... Jun 04 16:42:39 audit: BPF prog-id=75 op=LOAD Jun 04 16:42:39 systemd[1]: Starting systemd-resolved.service - Network Name Resolution... Jun 04 16:42:39 audit[1188]: AVC avc: denied { connectto } for pid=1188 comm="(emd-oomd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:39 audit[1188]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7fff46617d70 a2=33 a3=160 items=0 ppid=1 pid=1188 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(emd-oomd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) Jun 04 16:42:39 audit: PROCTITLE proctitle="(emd-oomd)" Jun 04 16:42:39 systemd[1]: systemd-update-done.service - Update is Completed was skipped because no trigger condition checks were met. Jun 04 16:42:39 audit[1189]: AVC avc: denied { connectto } for pid=1189 comm="(resolved)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:39 audit[1189]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffdb67fb3d0 a2=33 a3=160 items=0 ppid=1 pid=1189 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(resolved)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) Jun 04 16:42:40 systemd[1]: Starting polkit.service - Authorization Manager... Jun 04 16:42:40 audit: BPF prog-id=81 op=LOAD Jun 04 16:42:40 systemd[1]: Starting power-profiles-daemon.service - Power Profiles daemon... Jun 04 16:42:40 audit[1235]: AVC avc: denied { connectto } for pid=1235 comm="(polkitd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:40 audit[1235]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7fff2ed9fdb0 a2=33 a3=2 items=0 ppid=1 pid=1235 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(polkitd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) ... un 04 16:42:42 audit[1242]: AVC avc: denied { connectto } for pid=1242 comm="accounts-daemon" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:accountsd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:42 audit[1242]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=d a1=7fff4588b390 a2=33 a3=561cdd5c5f00 items=0 ppid=1 pid=1242 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="accounts-daemon" exe="/usr/libexec/accounts-daemon" subj=system_u:system_r:accountsd_t:s0 key=(null) Jun 04 16:42:42 audit: PROCTITLE proctitle="/usr/libexec/accounts-daemon" Jun 04 16:42:42 audit[1242]: AVC avc: denied { connectto } for pid=1242 comm="accounts-daemon" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:accountsd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 ... Jun 04 16:42:48 audit[1481]: AVC avc: denied { connectto } for pid=1481 comm="sddm-helper" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:48 audit[1481]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=11 a1=7ffed730b790 a2=33 a3=1 items=0 ppid=1461 pid=1481 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="sddm-helper" exe="/usr/libexec/sddm-helper" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null) ... Jun 04 16:42:48 systemd[1]: Starting user - User Manager for UID 1000... Jun 04 16:42:48 audit[1509]: AVC avc: denied { connectto } for pid=1509 comm="(systemd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:48 audit[1509]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffc52ab4f80 a2=33 a3=160 items=0 ppid=1 pid=1509 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(systemd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) ... Jun 04 16:42:49 audit[1218]: AVC avc: denied { connectto } for pid=1218 comm="auditd" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:auditd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:49 audit[1218]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=d a1=7ffd51652c10 a2=33 a3=4 items=0 ppid=1 pid=1218 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditd" exe="/usr/sbin/auditd" subj=system_u:system_r:auditd_t:s0 key=(null) ... Jun 04 16:42:53 audit[1824]: AVC avc: denied { connectto } for pid=1824 comm="pkla-check-auth" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:policykit_auth_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:42:53 audit[1824]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=a a1=7ffe6c7df2c0 a2=33 a3=4 items=0 ppid=1235 pid=1824 auid=4294967295 uid=114 gid=114 euid=114 suid=114 fsuid=114 egid=114 sgid=114 fsgid=114 tty=(none) ses=4294967295 comm="pkla-check-auth" exe="/usr/bin/pkla-check-authorization" subj=system_u:system_r:policykit_auth_t:s0 key=(null) ... Jun 04 16:43:27 audit[2549]: AVC avc: denied { connectto } for pid=2549 comm="cupsd" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:43:27 audit[2549]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=9 a1=7fffb54b7680 a2=33 a3=4 items=0 ppid=1 pid=2549 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="cupsd" exe="/usr/sbin/cupsd" subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 key=(null) ... Jun 04 16:49:35 audit[2953]: AVC avc: denied { connectto } for pid=2953 comm="(systemd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:49:35 audit[2953]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=c a1=7fff01fc7780 a2=33 a3=55ddd8e1a160 items=0 ppid=1 pid=2953 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=3 comm="(systemd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) ... Jun 04 16:50:32 systemd[1]: Started run-u82.service - systemd-stdio-bridge "-punix:path=\${XDG_RUNTIME_DIR}/bus". Jun 04 16:50:32 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=run-u82 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success' Jun 04 16:50:32 audit[3221]: AVC avc: denied { connectto } for pid=3221 comm="(o-bridge)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 Jun 04 16:50:32 audit[3221]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffdb2ab5ee0 a2=33 a3=160 items=0 ppid=1 pid=3221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(o-bridge)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null) These denials of polkitd, accounts-daemon, auditd, and pkla-check-authorization happened repeatedly as Plasma ran. I'll attach the journal. These denials happened on 2/2 boots. Reproducible: Always Steps to Reproduce: 1. Download Fedora Rawhide KDE live image Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso from https://koji.fedoraproject.org/koji/buildinfo?buildID=2460858 2. Boot the live image in a QEMU/KVM VM in GNOME Boxes with 4 GiB RAM, UEFI enabled, and 3D acceleration disabled. 3. Actual Results: systemd-nsresourced denials with selinux-policy-41.1-1.fc41 Expected Results: No denials should've happened.
Created attachment 2036341 [details] journal of boot of Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso containing systemd-nsresourced denials
One full entry and list of domains collected so far: type=PROCTITLE msg=audit(06/05/2024 06:26:07.497:1562) : proctitle=(systemd) type=PATH msg=audit(06/05/2024 06:26:07.497:1562) : item=0 name=/run/systemd/userdb/io.systemd.NamespaceResource inode=1062 dev=00:1b mode=socket,666 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:init_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(06/05/2024 06:26:07.497:1562) : cwd=/ type=SOCKADDR msg=audit(06/05/2024 06:26:07.497:1562) : saddr={ saddr_fam=local path=/run/systemd/userdb/io.systemd.NamespaceResource } type=SYSCALL msg=audit(06/05/2024 06:26:07.497:1562) : arch=x86_64 syscall=connect success=no exit=EACCES(Permission denied) a0=0x7 a1=0x7fffd13bee40 a2=0x33 a3=0x3 items=1 ppid=1 pid=65998 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=(systemd) exe=/usr/lib/systemd/systemd-executor subj=system_u:system_r:init_t:s0 key=(null) type=AVC msg=audit(06/05/2024 06:26:07.497:1562) : avc: denied { connectto } for pid=65998 comm=(systemd) path=/run/systemd/io.systemd.NamespaceResource scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 allow abrt_t systemd_nsresourced_t:unix_stream_socket connectto; allow accountsd_t systemd_nsresourced_t:unix_stream_socket connectto; allow auditd_t systemd_nsresourced_t:unix_stream_socket connectto; allow cupsd_t systemd_nsresourced_t:unix_stream_socket connectto; allow init_t systemd_nsresourced_t:unix_stream_socket connectto; allow local_login_t systemd_nsresourced_t:unix_stream_socket connectto; allow policykit_auth_t systemd_nsresourced_t:unix_stream_socket connectto; allow setroubleshootd_t systemd_nsresourced_t:unix_stream_socket connectto; allow staff_t systemd_nsresourced_t:unix_stream_socket connectto; allow xdm_t systemd_nsresourced_t:unix_stream_socket connectto;
Test coverage for this bug exists in a form of PR: * https://src.fedoraproject.org/tests/selinux/pull-request/512 The PR waits for a review.
*** Bug 2282040 has been marked as a duplicate of this bug. ***
*** Bug 2292502 has been marked as a duplicate of this bug. ***