Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: I started my system after an update. SELinux is preventing tuned-ppd from 'write' accesses on the sock_file /var/lib/sss/pipes/nss. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that tuned-ppd should be allowed write access on the nss sock_file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'tuned-ppd' --raw | audit2allow -M my-tunedppd # semodule -X 300 -i my-tunedppd.pp Additional Information: Source Context system_u:system_r:tuned_ppd_t:s0 Target Context system_u:object_r:sssd_var_lib_t:s0 Target Objects /var/lib/sss/pipes/nss [ sock_file ] Source tuned-ppd Source Path tuned-ppd Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages SELinux Policy RPM selinux-policy-targeted-41.39-1.fc41.noarch Local Policy RPM selinux-policy-targeted-41.39-1.fc41.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 6.14.6-200.fc41.x86_64 #1 SMP PREEMPT_DYNAMIC Fri May 9 19:55:50 UTC 2025 x86_64 Alert Count 2 First Seen 2025-04-17 19:37:53 EDT Last Seen 2025-05-18 11:40:30 EDT Local ID 991d9416-ec23-4a2f-99af-2afa7127d89b Raw Audit Messages type=AVC msg=audit(1747582830.333:224): avc: denied { write } for pid=4833 comm="tuned-ppd" name="nss" dev="dm-0" ino=1048662 scontext=system_u:system_r:tuned_ppd_t:s0 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=sock_file permissive=1 Hash: tuned-ppd,tuned_ppd_t,sssd_var_lib_t,sock_file,write Version-Release number of selected component: selinux-policy-targeted-41.39-1.fc41.noarch Additional info: reporter: libreport-2.17.15 comment: I started my system after an update. component: selinux-policy package: selinux-policy-targeted-41.39-1.fc41.noarch kernel: 6.14.6-200.fc41.x86_64 reason: SELinux is preventing tuned-ppd from 'write' accesses on the sock_file /var/lib/sss/pipes/nss. type: libreport hashmarkername: setroubleshoot component: selinux-policy
Created attachment 2090345 [details] File: description
Created attachment 2090346 [details] File: os_info
The following SELinux denial appears in enforcing mode: ---- type=PROCTITLE msg=audit(05/20/2025 05:13:21.134:659) : proctitle=/usr/bin/python3 -Es /usr/sbin/tuned-ppd -l type=PATH msg=audit(05/20/2025 05:13:21.134:659) : item=0 name=/var/lib/sss/pipes/nss inode=1699 dev=fd:02 mode=socket,666 ouid=sssd ogid=sssd rdev=00:00 obj=system_u:object_r:sssd_var_lib_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(05/20/2025 05:13:21.134:659) : cwd=/ type=SOCKADDR msg=audit(05/20/2025 05:13:21.134:659) : saddr={ saddr_fam=local path=/var/lib/sss/pipes/nss } type=SYSCALL msg=audit(05/20/2025 05:13:21.134:659) : arch=x86_64 syscall=connect success=no exit=ECONNREFUSED(Connection refused) a0=0x4 a1=0x7ffc85318ea0 a2=0x6e a3=0x100 items=1 ppid=1 pid=3211 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=tuned-ppd exe=/usr/bin/python3.13 subj=system_u:system_r:tuned_ppd_t:s0 key=(null) type=AVC msg=audit(05/20/2025 05:13:21.134:659) : avc: denied { write } for pid=3211 comm=tuned-ppd name=nss dev="vda2" ino=1699 scontext=system_u:system_r:tuned_ppd_t:s0 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=sock_file permissive=1 ---- # seinfo --permissive | grep tune tuned_ppd_t # rpm -qa seli\* selinux-policy-41.39-1.fc41.noarch selinux-policy-targeted-41.39-1.fc41.noarch #
The following SELinux denials appeared after reboot: ---- type=PROCTITLE msg=audit(05/20/2025 05:18:15.073:169) : proctitle=/usr/bin/python3 -Es /usr/sbin/tuned-ppd -l type=PATH msg=audit(05/20/2025 05:18:15.073:169) : item=0 name=/var/lib/sss/pipes/nss inode=80 dev=fd:02 mode=socket,666 ouid=sssd ogid=sssd rdev=00:00 obj=system_u:object_r:sssd_var_lib_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(05/20/2025 05:18:15.073:169) : cwd=/ type=SOCKADDR msg=audit(05/20/2025 05:18:15.073:169) : saddr={ saddr_fam=local path=/var/lib/sss/pipes/nss } type=SYSCALL msg=audit(05/20/2025 05:18:15.073:169) : arch=x86_64 syscall=connect success=yes exit=0 a0=0x4 a1=0x7ffd3d65c1d0 a2=0x6e a3=0x100 items=1 ppid=1 pid=982 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=tuned-ppd exe=/usr/bin/python3.13 subj=system_u:system_r:tuned_ppd_t:s0 key=(null) type=AVC msg=audit(05/20/2025 05:18:15.073:169) : avc: denied { connectto } for pid=982 comm=tuned-ppd path=/var/lib/sss/pipes/nss scontext=system_u:system_r:tuned_ppd_t:s0 tcontext=system_u:system_r:sssd_t:s0 tclass=unix_stream_socket permissive=1 type=AVC msg=audit(05/20/2025 05:18:15.073:169) : avc: denied { write } for pid=982 comm=tuned-ppd name=nss dev="vda2" ino=80 scontext=system_u:system_r:tuned_ppd_t:s0 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=sock_file permissive=1 ----
Test coverage for this bug exists in a form of PR: * https://src.fedoraproject.org/tests/selinux/pull-request/654 The PR waits for a review.
FEDORA-2025-eb98eb9e24 (selinux-policy-41.43-1.fc41) has been submitted as an update to Fedora 41. https://bodhi.fedoraproject.org/updates/FEDORA-2025-eb98eb9e24
FEDORA-2025-eb98eb9e24 has been pushed to the Fedora 41 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-eb98eb9e24` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-eb98eb9e24 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2025-eb98eb9e24 (selinux-policy-41.43-1.fc41) has been pushed to the Fedora 41 stable repository. If problem still persists, please make note of it in this bug report.