Bug 2290477 - systemd-nsresourced denials with selinux-policy-41.1-1.fc41
Summary: systemd-nsresourced denials with selinux-policy-41.1-1.fc41
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: Unspecified
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 2282040 2292502 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-06-04 21:32 UTC by Matt Fagnani
Modified: 2024-06-20 18:35 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-06-20 18:35:33 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)
journal of boot of Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso containing systemd-nsresourced denials (609.89 KB, text/plain)
2024-06-04 21:33 UTC, Matt Fagnani
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2170 0 None Draft Update policy for systemd-nsresourced 2024-06-14 17:40:03 UTC

Description Matt Fagnani 2024-06-04 21:32:22 UTC
I booted the Fedora Rawhide KDE live image Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso in a QEMU/KVM VM in GNOME Boxes in a Fedora 40 KDE host. There were many denials involving systemd-nsresourced with selinux-policy-41.1-1.fc41 during boot and after. systemd-nsresourced was denied writing to /sys/fs/cgroup/system.slice/systemd-nsresourced.service/memory.pressure when it started. 

Jun 04 16:42:35 systemd[1]: Starting systemd-nsresourced.service - Namespace Resource Manager...
Jun 04 16:42:35 systemd[1]: Starting systemd-userdbd.service - User Database Manager...
Jun 04 16:42:35 systemd[1]: Finished systemd-random-seed.service - Load/Save OS Random Seed.
Jun 04 16:42:35 systemd[1]: Finished systemd-udev-trigger.service - Coldplug All udev Devices.
Jun 04 16:42:35 systemd[1]: Finished systemd-journal-flush.service - Flush Journal to Persistent Storage.
Jun 04 16:42:35 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-journal-flush comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Jun 04 16:42:35 systemd[1]: Finished systemd-sysctl.service - Apply Kernel Variables.
Jun 04 16:42:35 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=systemd-sysctl comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Jun 04 16:42:35 audit[1060]: AVC avc:  denied  { write } for  pid=1060 comm="systemd-nsresou" name="memory.pressure" dev="cgroup2" ino=2686 scontext=system_u:system_r:systemd_nsresourced_t:s0 tcontext=system_u:object_r:cgroup_t:s0 tclass=file permissive=1
Jun 04 16:42:35 audit[1060]: SYSCALL arch=c000003e syscall=257 success=yes exit=8 a0=ffffff9c a1=7ffd660cde90 a2=80902 a3=0 items=0 ppid=1 pid=1060 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="systemd-nsresou" exe="/usr/lib/systemd/systemd-nsresourced" subj=system_u:system_r:systemd_nsresourced_t:s0 key=(null)

systemd-oomd, systemd-resolved, polkitd, accounts-daemon, sddm-helper, the systemd user daemons run by user and user, auditd, pkla-check-authorization, cupsd, and systemd-stdio-bridge were denied connecting to /run/systemd/io.systemd.NamespaceResource

Jun 04 16:42:39 systemd[1]: Starting systemd-oomd.service - Userspace Out-Of-Memory (OOM) Killer...
Jun 04 16:42:39 audit: BPF prog-id=75 op=LOAD
Jun 04 16:42:39 systemd[1]: Starting systemd-resolved.service - Network Name Resolution...
Jun 04 16:42:39 audit[1188]: AVC avc:  denied  { connectto } for  pid=1188 comm="(emd-oomd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:39 audit[1188]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7fff46617d70 a2=33 a3=160 items=0 ppid=1 pid=1188 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(emd-oomd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
Jun 04 16:42:39 audit: PROCTITLE proctitle="(emd-oomd)"
Jun 04 16:42:39 systemd[1]: systemd-update-done.service - Update is Completed was skipped because no trigger condition checks were met.
Jun 04 16:42:39 audit[1189]: AVC avc:  denied  { connectto } for  pid=1189 comm="(resolved)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:39 audit[1189]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffdb67fb3d0 a2=33 a3=160 items=0 ppid=1 pid=1189 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(resolved)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)

Jun 04 16:42:40 systemd[1]: Starting polkit.service - Authorization Manager...
Jun 04 16:42:40 audit: BPF prog-id=81 op=LOAD
Jun 04 16:42:40 systemd[1]: Starting power-profiles-daemon.service - Power Profiles daemon...
Jun 04 16:42:40 audit[1235]: AVC avc:  denied  { connectto } for  pid=1235 comm="(polkitd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:40 audit[1235]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7fff2ed9fdb0 a2=33 a3=2 items=0 ppid=1 pid=1235 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(polkitd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
...
un 04 16:42:42 audit[1242]: AVC avc:  denied  { connectto } for  pid=1242 comm="accounts-daemon" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:accountsd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:42 audit[1242]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=d a1=7fff4588b390 a2=33 a3=561cdd5c5f00 items=0 ppid=1 pid=1242 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="accounts-daemon" exe="/usr/libexec/accounts-daemon" subj=system_u:system_r:accountsd_t:s0 key=(null)
Jun 04 16:42:42 audit: PROCTITLE proctitle="/usr/libexec/accounts-daemon"
Jun 04 16:42:42 audit[1242]: AVC avc:  denied  { connectto } for  pid=1242 comm="accounts-daemon" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:accountsd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
...
Jun 04 16:42:48 audit[1481]: AVC avc:  denied  { connectto } for  pid=1481 comm="sddm-helper" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:xdm_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:48 audit[1481]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=11 a1=7ffed730b790 a2=33 a3=1 items=0 ppid=1461 pid=1481 auid=1000 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=1 comm="sddm-helper" exe="/usr/libexec/sddm-helper" subj=system_u:system_r:xdm_t:s0-s0:c0.c1023 key=(null)
...
Jun 04 16:42:48 systemd[1]: Starting user - User Manager for UID 1000...
Jun 04 16:42:48 audit[1509]: AVC avc:  denied  { connectto } for  pid=1509 comm="(systemd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:48 audit[1509]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffc52ab4f80 a2=33 a3=160 items=0 ppid=1 pid=1509 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(systemd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
...
Jun 04 16:42:49 audit[1218]: AVC avc:  denied  { connectto } for  pid=1218 comm="auditd" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:auditd_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:49 audit[1218]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=d a1=7ffd51652c10 a2=33 a3=4 items=0 ppid=1 pid=1218 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="auditd" exe="/usr/sbin/auditd" subj=system_u:system_r:auditd_t:s0 key=(null)
...
Jun 04 16:42:53 audit[1824]: AVC avc:  denied  { connectto } for  pid=1824 comm="pkla-check-auth" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:policykit_auth_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:42:53 audit[1824]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=a a1=7ffe6c7df2c0 a2=33 a3=4 items=0 ppid=1235 pid=1824 auid=4294967295 uid=114 gid=114 euid=114 suid=114 fsuid=114 egid=114 sgid=114 fsgid=114 tty=(none) ses=4294967295 comm="pkla-check-auth" exe="/usr/bin/pkla-check-authorization" subj=system_u:system_r:policykit_auth_t:s0 key=(null)
...
Jun 04 16:43:27 audit[2549]: AVC avc:  denied  { connectto } for  pid=2549 comm="cupsd" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:cupsd_t:s0-s0:c0.c1023 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:43:27 audit[2549]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=9 a1=7fffb54b7680 a2=33 a3=4 items=0 ppid=1 pid=2549 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="cupsd" exe="/usr/sbin/cupsd" subj=system_u:system_r:cupsd_t:s0-s0:c0.c1023 key=(null)
...
Jun 04 16:49:35 audit[2953]: AVC avc:  denied  { connectto } for  pid=2953 comm="(systemd)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:49:35 audit[2953]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=c a1=7fff01fc7780 a2=33 a3=55ddd8e1a160 items=0 ppid=1 pid=2953 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=3 comm="(systemd)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)
...
Jun 04 16:50:32 systemd[1]: Started run-u82.service - systemd-stdio-bridge "-punix:path=\${XDG_RUNTIME_DIR}/bus".
Jun 04 16:50:32 audit[1]: SERVICE_START pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='unit=run-u82 comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
Jun 04 16:50:32 audit[3221]: AVC avc:  denied  { connectto } for  pid=3221 comm="(o-bridge)" path="/run/systemd/io.systemd.NamespaceResource" scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0
Jun 04 16:50:32 audit[3221]: SYSCALL arch=c000003e syscall=42 success=no exit=-13 a0=7 a1=7ffdb2ab5ee0 a2=33 a3=160 items=0 ppid=1 pid=3221 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="(o-bridge)" exe="/usr/lib/systemd/systemd-executor" subj=system_u:system_r:init_t:s0 key=(null)

These denials of polkitd, accounts-daemon, auditd, and pkla-check-authorization happened repeatedly as Plasma ran. I'll attach the journal. These denials happened on 2/2 boots.

Reproducible: Always

Steps to Reproduce:
1. Download Fedora Rawhide KDE live image Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso from https://koji.fedoraproject.org/koji/buildinfo?buildID=2460858
2. Boot the live image in a QEMU/KVM VM in GNOME Boxes with 4 GiB RAM, UEFI enabled, and 3D acceleration disabled.
3.
Actual Results:  
systemd-nsresourced denials with selinux-policy-41.1-1.fc41

Expected Results:  
No denials should've happened.

Comment 1 Matt Fagnani 2024-06-04 21:33:37 UTC
Created attachment 2036341 [details]
journal of boot of Fedora-KDE-Live-x86_64-Rawhide-20240604.n.0.iso containing systemd-nsresourced denials

Comment 2 Zdenek Pytela 2024-06-05 14:14:47 UTC
One full entry and list of domains collected so far:

type=PROCTITLE msg=audit(06/05/2024 06:26:07.497:1562) : proctitle=(systemd) 
type=PATH msg=audit(06/05/2024 06:26:07.497:1562) : item=0 name=/run/systemd/userdb/io.systemd.NamespaceResource inode=1062 dev=00:1b mode=socket,666 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:init_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(06/05/2024 06:26:07.497:1562) : cwd=/ 
type=SOCKADDR msg=audit(06/05/2024 06:26:07.497:1562) : saddr={ saddr_fam=local path=/run/systemd/userdb/io.systemd.NamespaceResource } 
type=SYSCALL msg=audit(06/05/2024 06:26:07.497:1562) : arch=x86_64 syscall=connect success=no exit=EACCES(Permission denied) a0=0x7 a1=0x7fffd13bee40 a2=0x33 a3=0x3 items=1 ppid=1 pid=65998 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=(systemd) exe=/usr/lib/systemd/systemd-executor subj=system_u:system_r:init_t:s0 key=(null) 
type=AVC msg=audit(06/05/2024 06:26:07.497:1562) : avc:  denied  { connectto } for  pid=65998 comm=(systemd) path=/run/systemd/io.systemd.NamespaceResource scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:systemd_nsresourced_t:s0 tclass=unix_stream_socket permissive=0 

allow abrt_t systemd_nsresourced_t:unix_stream_socket connectto;
allow accountsd_t systemd_nsresourced_t:unix_stream_socket connectto;
allow auditd_t systemd_nsresourced_t:unix_stream_socket connectto;
allow cupsd_t systemd_nsresourced_t:unix_stream_socket connectto;
allow init_t systemd_nsresourced_t:unix_stream_socket connectto;
allow local_login_t systemd_nsresourced_t:unix_stream_socket connectto;
allow policykit_auth_t systemd_nsresourced_t:unix_stream_socket connectto;
allow setroubleshootd_t systemd_nsresourced_t:unix_stream_socket connectto;
allow staff_t systemd_nsresourced_t:unix_stream_socket connectto;
allow xdm_t systemd_nsresourced_t:unix_stream_socket connectto;

Comment 3 Milos Malik 2024-06-13 16:02:01 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/512

The PR waits for a review.

Comment 4 Zdenek Pytela 2024-06-17 15:36:03 UTC
*** Bug 2282040 has been marked as a duplicate of this bug. ***

Comment 5 Zdenek Pytela 2024-06-17 16:01:09 UTC
*** Bug 2292502 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.