Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-1771

avc: denied { ioctl } for pid=5170 comm="leapp3" path="/root/tmp_leapp_py3/leapp3" dev="dm-0" observed after In-place upgrading RHEL8.6 to RHEL9

    • Minor
    • sst_upgrades
    • 1
    • False
    • Hide

      None

      Show
      None
    • If docs needed, set a value

      Description of problem:
      avc: denied

      { ioctl } for pid=5170 comm="leapp3" path="/root/tmp_leapp_py3/leapp3" dev="dm-0" observed after In-place upgrading RHEL8.6 to RHEL9

      Version-Release number of selected component (if applicable):


      How reproducible:
      reproduced one time

      Steps to Reproduce:
      1. install RHEL-8.6.0-20211212.3 BaseOS x86_64
      2. follow below steps to upgrade to RHEL9
      # curl -o /etc/yum.repos.d/oam-group-leapp-rhel-8.repo https://copr.fedorainfracloud.org/coprs/g/oamg/leapp/repo/epel-8/group_oamg-leapp-epel-8.repo
      # dnf install leapp-upgrade-el8toel9 -y
      # curl -kLO https://gitlab.cee.redhat.com/leapp/oamg-rhel7-vagrant/raw/master/roles/init/files/prepare_test_env.sh
      # source prepare_test_env.sh
      # get_data_files
      # curl -o /etc/leapp/files/leapp_upgrade_repositories.repo -k
      http://file.emea.redhat.com/~mreznik/tmp/leapp_upgrade_repositories.repo
      # leapp preupgrade --debug --no-rhsm
      # leapp upgrade --debug --no-rhsm --reboot

      3..

      Actual results:


      Expected results:


      Additional info:
      beaker job: J:6093440
      # cat avc.log

      SELinux status: enabled
      SELinuxfs mount: /sys/fs/selinux
      SELinux root directory: /etc/selinux
      Loaded policy name: targeted
      Current mode: permissive
      Mode from config file: permissive
      Policy MLS status: enabled
      Policy deny_unknown status: allowed
      Memory protection checking: actual (secure)
      Max kernel policy version: 33
      selinux-policy-34.1.19-1.el9.noarch
      ----
      time->Tue Dec 14 02:35:30 2021
      type=PROCTITLE msg=audit(1639467330.462:60): proctitle="(leapp3)"
      type=SYSCALL msg=audit(1639467330.462:60): arch=c000003e syscall=16 success=no exit=-25 a0=4 a1=5401 a2=7ffcee8ff5f0 a3=8 items=0 ppid=1 pid=5170 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="leapp3" exe="/usr/bin/python3.9" subj=system_u:system_r:init_t:s0 key=(null)
      type=AVC msg=audit(1639467330.462:60): avc: denied { ioctl }

      for pid=5170 comm="leapp3" path="/root/tmp_leapp_py3/leapp3" dev="dm-0" ino=201327362 ioctlcmd=0x5401 scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:admin_home_t:s0 tclass=file permissive=1

            leapp-notifications leapp-notifications
            yizhan@redhat.com Yi Zhang
            leapp-notifications leapp-notifications
            Martin Kluson Martin Kluson
            Votes:
            0 Vote for this issue
            Watchers:
            21 Start watching this issue

              Created:
              Updated: