Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.

Bug 910837

Summary: AVC problem when kadmind|krb5kdc try to check existence of /etc/passwd
Product: Red Hat Enterprise Linux 7 Reporter: David Spurek <dspurek>
Component: selinux-policyAssignee: Miroslav Grepl <mgrepl>
Status: CLOSED CURRENTRELEASE QA Contact: Milos Malik <mmalik>
Severity: medium Docs Contact:
Priority: unspecified    
Version: 7.0CC: dspurek, ebenes, mmalik
Target Milestone: rc   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-13 10:32:37 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description David Spurek 2013-02-13 16:51:30 UTC
Description of problem:
AVC problem when kadmind|krb5kdc try to check existence of /etc/passwd

Version-Release number of selected component (if applicable):
selinux-policy-3.11.1-75.el7.noarch

How reproducible:


Steps to Reproduce:
1.
2.
3.
  
Actual results:
avc messages

Expected results:
no avc messages

Additional info:

Info: Searching AVC errors produced since 1360617036.78 (Mon Feb 11 16:10:36 2013)
Searching logs...
Running '/usr/bin/env LC_ALL=en_US.UTF-8 /sbin/ausearch -m AVC -m USER_AVC -m SELINUX_ERR -ts 02/11/2013 16:10:36 < /dev/null >/mnt/testarea/tmp.rhts-db-submit-result.uZk4T3 2>&1'
----
time->Mon Feb 11 16:10:48 2013
type=SYSCALL msg=audit(1360617048.014:756): arch=c000003e syscall=4 success=no exit=-13 a0=7f373ef6c5ee a1=7fffd76b4130 a2=7fffd76b4130 a3=7f3747b86060 items=0 ppid=1 pid=18038 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 ses=4294967295 tty=(none) comm="kadmind" exe="/usr/sbin/kadmind" subj=system_u:system_r:kadmind_t:s0 key=(null)
type=AVC msg=audit(1360617048.014:756): avc:  denied  { getattr } for  pid=18038 comm="kadmind" path="/etc/passwd" dev="dm-1" ino=69403621 scontext=system_u:system_r:kadmind_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Mon Feb 11 16:10:48 2013
type=SYSCALL msg=audit(1360617048.021:757): arch=c000003e syscall=4 success=no exit=-13 a0=7f373ef6c5ee a1=7fffd76b4130 a2=7fffd76b4130 a3=7f3747b86060 items=0 ppid=1 pid=18038 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 ses=4294967295 tty=(none) comm="kadmind" exe="/usr/sbin/kadmind" subj=system_u:system_r:kadmind_t:s0 key=(null)
type=AVC msg=audit(1360617048.021:757): avc:  denied  { getattr } for  pid=18038 comm="kadmind" path="/etc/passwd" dev="dm-1" ino=69403621 scontext=system_u:system_r:kadmind_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Mon Feb 11 16:10:53 2013
type=SYSCALL msg=audit(1360617053.679:760): arch=c000003e syscall=4 success=no exit=-13 a0=7fd6e1c685ee a1=7fff74ee8560 a2=7fff74ee8560 a3=2cf8fe2b0ff7d0a6 items=0 ppid=1 pid=18101 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 ses=4294967295 tty=(none) comm="krb5kdc" exe="/usr/sbin/krb5kdc" subj=system_u:system_r:krb5kdc_t:s0 key=(null)
type=AVC msg=audit(1360617053.679:760): avc:  denied  { getattr } for  pid=18101 comm="krb5kdc" path="/etc/passwd" dev="dm-1" ino=69403621 scontext=system_u:system_r:krb5kdc_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----
time->Mon Feb 11 16:10:53 2013
type=SYSCALL msg=audit(1360617053.673:759): arch=c000003e syscall=4 success=no exit=-13 a0=7fd6e1c685ee a1=7fff74ee8560 a2=7fff74ee8560 a3=416f99298f54abf6 items=0 ppid=1 pid=18101 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 ses=4294967295 tty=(none) comm="krb5kdc" exe="/usr/sbin/krb5kdc" subj=system_u:system_r:krb5kdc_t:s0 key=(null)
type=AVC msg=audit(1360617053.673:759): avc:  denied  { getattr } for  pid=18101 comm="krb5kdc" path="/etc/passwd" dev="dm-1" ino=69403621 scontext=system_u:system_r:krb5kdc_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
Fail: AVC messages found.
Checking for errors...
Using stronger AVC checks.
	Define empty RHTS_OPTION_STRONGER_AVC parameter if this causes any problems.
Running 'cat /mnt/testarea/tmp.rhts-db-submit-result.uZk4T3 | /sbin/ausearch -m AVC -m SELINUX_ERR'
Fail: AVC messages found.
Running 'cat %s | /sbin/ausearch -m USER_AVC >/mnt/testarea/tmp.rhts-db-submit-result.WniwJP 2>&1'
Info: No AVC messages found.
/bin/grep 'avc: ' /mnt/testarea/dmesg.log | /bin/grep --invert-match TESTOUT.log
No AVC messages found in dmesg
Running '/usr/sbin/sestatus'
SELinux status:                 enabled
SELinuxfs mount:                /sys/fs/selinux
SELinux root directory:         /etc/selinux
Loaded policy name:             targeted
Current mode:                   enforcing
Mode from config file:          enforcing
Policy MLS status:              enabled
Policy deny_unknown status:     allowed
Max kernel policy version:      28
Running 'rpm -q selinux-policy || true'
selinux-policy-3.11.1-75.el7.noarch

Comment 1 Milos Malik 2013-02-14 08:52:06 UTC
The automated test produced following AVCs in permissive mode:
----
type=PATH msg=audit(02/14/2013 09:48:25.145:11240) : item=0 name=/etc/passwd inode=397651 dev=08:04 mode=file,644 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:passwd_file_t:s0 
type=CWD msg=audit(02/14/2013 09:48:25.145:11240) :  cwd=/ 
type=SYSCALL msg=audit(02/14/2013 09:48:25.145:11240) : arch=x86_64 syscall=stat success=yes exit=0 a0=0x7f5283c195ee a1=0x7fff795349f0 a2=0x7fff795349f0 a3=0xb190d7cb28478aec items=1 ppid=1 pid=8533 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root ses=unset tty=(none) comm=kadmind exe=/usr/sbin/kadmind subj=system_u:system_r:kadmind_t:s0 key=(null) 
type=AVC msg=audit(02/14/2013 09:48:25.145:11240) : avc:  denied  { getattr } for  pid=8533 comm=kadmind path=/etc/passwd dev="sda4" ino=397651 scontext=system_u:system_r:kadmind_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file 
----
type=PATH msg=audit(02/14/2013 09:48:25.145:11241) : item=0 name=/etc/passwd inode=397651 dev=08:04 mode=file,644 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:passwd_file_t:s0 
type=CWD msg=audit(02/14/2013 09:48:25.145:11241) :  cwd=/ 
type=SYSCALL msg=audit(02/14/2013 09:48:25.145:11241) : arch=x86_64 syscall=open success=yes exit=5 a0=0x7f5283c195ee a1=O_RDONLY a2=0x1b6 a3=0x238 items=1 ppid=1 pid=8533 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root ses=unset tty=(none) comm=kadmind exe=/usr/sbin/kadmind subj=system_u:system_r:kadmind_t:s0 key=(null) 
type=AVC msg=audit(02/14/2013 09:48:25.145:11241) : avc:  denied  { open } for  pid=8533 comm=kadmind path=/etc/passwd dev="sda4" ino=397651 scontext=system_u:system_r:kadmind_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file 
type=AVC msg=audit(02/14/2013 09:48:25.145:11241) : avc:  denied  { read } for  pid=8533 comm=kadmind name=passwd dev="sda4" ino=397651 scontext=system_u:system_r:kadmind_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file 
----
type=PATH msg=audit(02/14/2013 09:48:30.445:11244) : item=0 name=/etc/passwd inode=397651 dev=08:04 mode=file,644 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:passwd_file_t:s0 
type=CWD msg=audit(02/14/2013 09:48:30.445:11244) :  cwd=/ 
type=SYSCALL msg=audit(02/14/2013 09:48:30.445:11244) : arch=x86_64 syscall=open success=yes exit=5 a0=0x7f72273ed5ee a1=O_RDONLY a2=0x1b6 a3=0x238 items=1 ppid=1 pid=8557 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root ses=unset tty=(none) comm=krb5kdc exe=/usr/sbin/krb5kdc subj=system_u:system_r:krb5kdc_t:s0 key=(null) 
type=AVC msg=audit(02/14/2013 09:48:30.445:11244) : avc:  denied  { open } for  pid=8557 comm=krb5kdc path=/etc/passwd dev="sda4" ino=397651 scontext=system_u:system_r:krb5kdc_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file 
type=AVC msg=audit(02/14/2013 09:48:30.445:11244) : avc:  denied  { read } for  pid=8557 comm=krb5kdc name=passwd dev="sda4" ino=397651 scontext=system_u:system_r:krb5kdc_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file 
----
type=PATH msg=audit(02/14/2013 09:48:30.445:11243) : item=0 name=/etc/passwd inode=397651 dev=08:04 mode=file,644 ouid=root ogid=root rdev=00:00 obj=system_u:object_r:passwd_file_t:s0 
type=CWD msg=audit(02/14/2013 09:48:30.445:11243) :  cwd=/ 
type=SYSCALL msg=audit(02/14/2013 09:48:30.445:11243) : arch=x86_64 syscall=stat success=yes exit=0 a0=0x7f72273ed5ee a1=0x7fff8f93d490 a2=0x7fff8f93d490 a3=0x3ec0ea1807c31021 items=1 ppid=1 pid=8557 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root ses=unset tty=(none) comm=krb5kdc exe=/usr/sbin/krb5kdc subj=system_u:system_r:krb5kdc_t:s0 key=(null) 
type=AVC msg=audit(02/14/2013 09:48:30.445:11243) : avc:  denied  { getattr } for  pid=8557 comm=krb5kdc path=/etc/passwd dev="sda4" ino=397651 scontext=system_u:system_r:krb5kdc_t:s0 tcontext=system_u:object_r:passwd_file_t:s0 tclass=file
----

Comment 2 Miroslav Grepl 2013-02-25 16:25:05 UTC
Added to rawhide.

Comment 4 Ludek Smid 2014-06-13 10:32:37 UTC
This request was resolved in Red Hat Enterprise Linux 7.0.

Contact your manager or support representative in case you have further questions about the request.