Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-148292

Fix selinux AVC denial when telemetry is enabled [rhel-10]

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Normal Normal
    • rhel-10.2
    • rhel-10.2
    • ansible-core
    • None
    • ansible-core-2.16.16-2.el10
    • None
    • Moderate
    • 1
    • None
    • 2
    • QE ack, Dev ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • PDE - Install - Sprint 2026-06
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      What were you trying to do that didn't work?

      When running under the insights-client via the systemd timer, the following avc denial was encountered:

      type=PROCTITLE msg=audit(01/30/2026 01:45:17.229:227) : proctitle=python3 /usr/share/ansible/telemetry/telemetry.py 
      
      type=PATH msg=audit(01/30/2026 01:45:17.229:227) : item=1 name=/root/.ansible/tmp/ansible-local-997364he_t5m nametype=CREATE cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
      
      type=PATH msg=audit(01/30/2026 01:45:17.229:227) : item=0 name=/root/.ansible/tmp/ inode=101256459 dev=fd:00 mode=dir,700 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:admin_home_t:s0 nametype=PARENT cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
      
      type=CWD msg=audit(01/30/2026 01:45:17.229:227) : cwd=/ 
      
      type=SYSCALL msg=audit(01/30/2026 01:45:17.229:227) : arch=x86_64 syscall=mkdir success=no exit=EACCES(Permission denied) a0=0x7ff94a8a76b0 a1=0700 a2=0x0 a3=0x7ff94c111cb8 items=2 ppid=9972 pid=9973 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=python3 exe=/usr/bin/python3.12 subj=system_u:system_r:insights_core_t:s0 key=(null) 
      
      type=AVC msg=audit(01/30/2026 01:45:17.229:227) : avc:  denied  { create } for  pid=9973 comm=python3 name=ansible-local-997364he_t5m scontext=system_u:system_r:insights_core_t:s0 tcontext=system_u:object_r:admin_home_t:s0 tclass=dir permissive=0
      

              dsavinea@redhat.com Dimitri Savineau
              dsavinea@redhat.com Dimitri Savineau
              Dimitri Savineau Dimitri Savineau
              Matt Clay Matt Clay
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Created:
                Updated: