Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1592145
Summary: | SELinux is preventing qemu-ga from 'read' accesses on the file dev. | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | ricky.tigg |
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | unspecified | Docs Contact: | |
Priority: | unspecified | ||
Version: | 28 | CC: | cwawak, dwalsh, lvrabec, mgrepl, plautrba |
Target Milestone: | --- | Keywords: | Reopened |
Target Release: | --- | ||
Hardware: | x86_64 | ||
OS: | Unspecified | ||
Whiteboard: | abrt_hash:f8eb11b56eed8fa92038e1c36149c067f63396601b6b7916f171586cb78c5496; | ||
Fixed In Version: | selinux-policy-3.14.1-36.fc28 selinux-policy-3.14.1-44.fc28 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-10-09 03:09:54 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
ricky.tigg
2018-06-17 21:03:17 UTC
selinux-policy-3.14.1-36.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-1050fb248b selinux-policy-3.14.1-36.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-1050fb248b selinux-policy-3.14.1-36.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report. Still seeing this w/ selinux-policy-3.14.1-40.fc28.noarch SELinux is preventing qemu-ga from read access on the file dev. ***** Plugin catchall (100. confidence) suggests ************************** If you believe that qemu-ga should be allowed read access on the dev file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing: # ausearch -c 'qemu-ga' --raw | audit2allow -M my-qemuga # semodule -X 300 -i my-qemuga.pp Additional Information: Source Context system_u:system_r:virt_qemu_ga_t:s0 Target Context system_u:object_r:proc_net_t:s0 Target Objects dev [ file ] Source qemu-ga Source Path qemu-ga Port <Unknown> Host fedorashell Source RPM Packages Target RPM Packages filesystem-3.8-2.fc28.x86_64 Policy RPM selinux-policy-3.14.1-40.fc28.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name fedorashell Platform Linux fedorashell 4.17.14-202.fc28.x86_64 #1 SMP Wed Aug 15 12:29:25 UTC 2018 x86_64 x86_64 Alert Count 65124 First Seen 2018-08-17 13:30:39 EDT Last Seen 2018-09-09 10:16:05 EDT Local ID f5489cc8-6995-4cf4-bfc4-b75a82a74653 Raw Audit Messages type=AVC msg=audit(1536502565.78:15568): avc: denied { read } for pid=771 comm="qemu-ga" name="dev" dev="proc" ino=4026532012 scontext=system_u:system_r:virt_qemu_ga_t:s0 tcontext=system_u:object_r:proc_net_t:s0 tclass=file permissive=0 Hash: qemu-ga,virt_qemu_ga_t,proc_net_t,file,read selinux-policy-3.14.1-44.fc28 has been submitted as an update to Fedora 28. https://bodhi.fedoraproject.org/updates/FEDORA-2018-5e18426088 selinux-policy-3.14.1-44.fc28 has been pushed to the Fedora 28 testing repository. If problems still persist, please make note of it in this bug report. See https://fedoraproject.org/wiki/QA:Updates_Testing for instructions on how to install test updates. You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2018-5e18426088 selinux-policy-3.14.1-44.fc28 has been pushed to the Fedora 28 stable repository. If problems still persist, please make note of it in this bug report. |