Bug 2368281 - SELinux is preventing iio-sensor-prox from 'sendto' accesses on the unix_dgram_socket /systemd/journal/socket.
Summary: SELinux is preventing iio-sensor-prox from 'sendto' accesses on the unix_dgra...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 42
Hardware: Unspecified
OS: Linux
low
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-23 16:01 UTC by BubbaTex
Modified: 2025-06-07 06:46 UTC (History)
7 users (show)

Fixed In Version: selinux-policy-41.43-1.fc42
Clone Of:
Environment:
Last Closed: 2025-06-07 06:46:26 UTC
Type: ---
Embargoed:
zpytela: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2718 0 None open Allow iio-sensor-proxy sendto to journald over a unix datagram socket 2025-06-04 14:54:42 UTC
Red Hat Issue Tracker FC-1692 0 None None None 2025-05-26 07:21:18 UTC

Description BubbaTex 2025-05-23 16:01:45 UTC
Additional Information:
Source Context                system_u:system_r:iiosensorproxy_t:s0
Target Context                system_u:system_r:kernel_t:s0
Target Objects                /systemd/journal/socket [ unix_dgram_socket ]
Source                        iio-sensor-prox
Source Path                   iio-sensor-prox
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
SELinux Policy RPM            selinux-policy-targeted-41.36-1.fc42.noarch
Local Policy RPM              selinux-policy-targeted-41.36-1.fc42.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.14.2-300.fc42.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Thu Apr 10 21:50:55 UTC 2025
                              x86_64
Alert Count                   8
First Seen                    2025-04-17 03:01:48 EEST
Last Seen                     2025-04-18 21:31:32 EEST
Local ID                      44fe3060-74a0-4e3d-8237-e04bd7335142

Raw Audit Messages
type=AVC msg=audit(1745001092.22:111): avc:  denied  { sendto } for  pid=815 comm="iio-sensor-prox" path="/systemd/journal/socket" scontext=system_u:system_r:iiosensorproxy_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=unix_dgram_socket permissive=0


Hash: iio-sensor-prox,iiosensorproxy_t,kernel_t,unix_dgram_socket,sendto

Reproducible: Always

Steps to Reproduce:
I don't know. The message just shows up in my SEL Alert browser.
Actual Results:
SELinux blocks unix socket access for iio_sensor_proxy, creating an alert

Expected Results:
no alert?

Comment 1 Fedora Update System 2025-06-04 19:42:54 UTC
FEDORA-2025-f9f097f491 (selinux-policy-41.43-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9f097f491

Comment 2 Fedora Update System 2025-06-05 02:35:55 UTC
FEDORA-2025-f9f097f491 has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-f9f097f491`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-f9f097f491

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 3 Fedora Update System 2025-06-07 06:46:26 UTC
FEDORA-2025-f9f097f491 (selinux-policy-41.43-1.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.