Note: This is a public test instance of Red Hat Bugzilla. The data contained within is a snapshot of the live data so any changes you make will not be reflected in the production Bugzilla. Email is disabled so feel free to test any aspect of the site that you want. File any problems you find or give feedback at bugzilla.redhat.com.
Bug 1371676 - SELinux is preventing iw from 'write' accesses on the file /run/tlp/lock_tlp.
Summary: SELinux is preventing iw from 'write' accesses on the file /run/tlp/lock_tlp.
Keywords:
Status: CLOSED DUPLICATE of bug 1399848
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 25
Hardware: x86_64
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:7bb98eff09db578f92e6b6786d9...
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-08-30 18:50 UTC by Heiko Adams
Modified: 2017-03-15 14:39 UTC (History)
26 users (show)

Fixed In Version: selinux-policy-3.13.1-225.1.fc25
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-12-08 18:22:38 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Heiko Adams 2016-08-30 18:50:23 UTC
Description of problem:
SELinux is preventing iw from 'write' accesses on the file /run/tlp/lock_tlp.

*****  Plugin catchall (100. confidence) suggests   **************************

If sie denken, dass es iw standardmässig erlaubt sein sollte, write Zugriff auf lock_tlp file zu erhalten.
Then sie sollten dies als Fehler melden.
Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen.
Do
allow this access for now by executing:
# ausearch -c 'iw' --raw | audit2allow -M my-iw
# semodule -X 300 -i my-iw.pp

Additional Information:
Source Context                system_u:system_r:ifconfig_t:s0-s0:c0.c1023
Target Context                system_u:object_r:var_run_t:s0
Target Objects                /run/tlp/lock_tlp [ file ]
Source                        iw
Source Path                   iw
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           
Policy RPM                    selinux-policy-3.13.1-211.fc25.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 4.8.0-0.rc2.git3.1.fc25.x86_64 #1
                              SMP Fri Aug 19 14:24:04 UTC 2016 x86_64 x86_64
Alert Count                   26
First Seen                    2016-08-29 20:03:44 CEST
Last Seen                     2016-08-30 20:47:22 CEST
Local ID                      43dad104-73a2-45b1-91c1-ec1d5dcad3ec

Raw Audit Messages
type=AVC msg=audit(1472582842.991:459): avc:  denied  { write } for  pid=21934 comm="ethtool" path="/run/tlp/lock_tlp" dev="tmpfs" ino=24516 scontext=system_u:system_r:ifconfig_t:s0-s0:c0.c1023 tcontext=system_u:object_r:var_run_t:s0 tclass=file permissive=0


Hash: iw,ifconfig_t,var_run_t,file,write

Version-Release number of selected component:
selinux-policy-3.13.1-211.fc25.noarch

Additional info:
reporter:       libreport-2.7.2
hashmarkername: setroubleshoot
kernel:         4.8.0-0.rc2.git3.1.fc25.x86_64
type:           libreport

Comment 1 Fedora Admin XMLRPC Client 2016-09-27 15:05:00 UTC
This package has changed ownership in the Fedora Package Database.  Reassigning to the new owner of this component.

Comment 2 Gerardo Rosales 2016-10-04 05:14:23 UTC
Description of problem:
I was working with a couple of files (in a USB memory) then closed my laptop lid to do other things. I returned around 2 hours later 
log in and the selinux message appeared.

Didn't try again.

Version-Release number of selected component:
selinux-policy-3.13.1-215.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.0-0.rc8.git0.1.fc25.x86_64
type:           libreport

Comment 3 Gerardo Rosales 2016-10-13 18:04:10 UTC
Description of problem:
Closed laptop lid, after 20 minutes logged back in and got the alert notification.

Version-Release number of selected component:
selinux-policy-3.13.1-219.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.1-1.fc25.x86_64
type:           libreport

Comment 4 Oliver Jan Krylow 2016-10-29 07:25:54 UTC
Description of problem:
Unplugged AC from Laptop.

Version-Release number of selected component:
selinux-policy-3.13.1-220.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.4-301.fc25.x86_64
type:           libreport

Comment 5 Sorawit Kongnurat 2016-11-08 06:07:39 UTC
Description of problem:
The error happens randomly after installing tlp and tlp-rdw from the fedora's repositories.

Version-Release number of selected component:
selinux-policy-3.13.1-222.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.6-300.fc25.x86_64
type:           libreport

Comment 6 Nate Graham 2016-11-21 03:16:04 UTC
Description of problem:
Looks like iw doesn't have access to this file, whose existence is intentional since I installed tlp to improve battery life on my laptop (and it worked!).

Version-Release number of selected component:
selinux-policy-3.13.1-216.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.0-0.rc7.git0.1.fc25.x86_64
type:           libreport

Comment 7 Frank Büttner 2016-11-24 10:49:26 UTC
Description of problem:
Plug in the power supply

Version-Release number of selected component:
selinux-policy-3.13.1-224.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.8-300.fc25.x86_64
type:           libreport

Comment 8 Frank Büttner 2016-11-26 18:49:32 UTC
Description of problem:
remove the power adapter

Version-Release number of selected component:
selinux-policy-3.13.1-224.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.8-300.fc25.x86_64
type:           libreport

Comment 9 fhmpaetow 2016-11-28 20:10:52 UTC
Description of problem:
I installed tlp. I believe it should work that way.

Best regards,
Felix

Version-Release number of selected component:
selinux-policy-3.13.1-224.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.8-300.fc25.x86_64
type:           libreport

Comment 10 Fedora Update System 2016-11-29 17:03:39 UTC
selinux-policy-3.13.1-225.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-9d027c3768

Comment 11 gspurki 2016-12-02 10:04:35 UTC
Description of problem:
TLP installed:

If unplug powerplug the state of tlp has to change to Bat

Version-Release number of selected component:
selinux-policy-3.13.1-224.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.10-300.fc25.x86_64
type:           libreport

Comment 12 Fedora Update System 2016-12-03 04:31:20 UTC
selinux-policy-3.13.1-225.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-9d027c3768

Comment 13 Fedora Update System 2016-12-05 17:02:10 UTC
selinux-policy-3.13.1-225.1.fc25 has been submitted as an update to Fedora 25. https://bodhi.fedoraproject.org/updates/FEDORA-2016-e3864b8972

Comment 14 josh 2016-12-07 00:42:29 UTC
Description of problem:
dnf install tlp
Afterwards, notification appearing regarding SELinux policy blocking access to file.

Version-Release number of selected component:
selinux-policy-3.13.1-224.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.10-300.fc25.x86_64
type:           libreport

Comment 15 Fedora Update System 2016-12-07 02:25:30 UTC
selinux-policy-3.13.1-225.1.fc25 has been pushed to the Fedora 25 testing repository. If problems still persist, please make note of it in this bug report.
See https://fedoraproject.org/wiki/QA:Updates_Testing for
instructions on how to install test updates.
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2016-e3864b8972

Comment 16 Fedora Update System 2016-12-08 18:22:38 UTC
selinux-policy-3.13.1-225.1.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 17 Andrew Rembrandt 2016-12-17 14:57:39 UTC
Description of problem:
Ran the following as root (on F25):
dnf install tlp tlp-rdw

Version-Release number of selected component:
selinux-policy-3.13.1-225.3.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.7.4-994.surfacepro3.fc25.x86_64
type:           libreport

Comment 18 arturpolak1 2017-01-07 21:22:27 UTC
Description of problem:
first run of tlp, disabling powertop service, AVC error...

Version-Release number of selected component:
selinux-policy-3.13.1-225.3.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.8.15-300.fc25.x86_64
type:           libreport

Comment 19 Gerardo Rosales 2017-01-08 03:30:52 UTC
Fedora 25 Xfce, still getting this issue.

1. Everytime I unplug/plug the laptop to the power source
2. When the laptop lid is closed/open

selinux-policy.noarch 3.13.1-225.3.fc25
kernel: 4.8.15-300.fc25.x86_64

Comment 20 arturpolak1 2017-01-24 00:26:02 UTC
Description of problem:
plug in AC adapter

Version-Release number of selected component:
selinux-policy-3.13.1-225.6.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.9.4-201.fc25.x86_64
type:           libreport

Comment 21 Jason D. Clinton 2017-03-06 02:17:10 UTC
Description of problem:
No custom configuration of TLP; this appears to be an as-shipped SELinux violation.

Version-Release number of selected component:
selinux-policy-3.13.1-225.11.fc25.noarch

Additional info:
reporter:       libreport-2.8.0
hashmarkername: setroubleshoot
kernel:         4.9.13-200.fc25.x86_64
type:           libreport

Comment 22 Jason D. Clinton 2017-03-06 02:18:47 UTC
Please reopen this bug.

Comment 23 Fernando Collova 2017-03-08 00:28:02 UTC
As stated above, this is still happening, the update didn't solve it. Please reopen this bug.

Comment 24 Yamin 2017-03-13 14:43:29 UTC

*** This bug has been marked as a duplicate of bug 1399848 ***

Comment 25 arturpolak1 2017-03-15 14:39:14 UTC
*** Bug 1432515 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.