Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-27222

[RHEL-8.9] avc: denied { read } for pid=598 comm="systemd-journal" name="invocation:chronyd.service" dev="tmpfs" ino=17130 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=lnk_file permissive=1

    • None
    • None
    • sst_security_selinux
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      SELinux status:                 enabled
      SELinuxfs mount:                /sys/fs/selinux
      SELinux root directory:         /etc/selinux
      Loaded policy name:             targeted
      Current mode:                   permissive
      Mode from config file:          permissive
      Policy MLS status:              enabled
      Policy deny_unknown status:     allowed
      Memory protection checking:     actual (secure)
      Max kernel policy version:      33
      selinux-policy-3.14.3-128.el8_9.1.noarch
      ----
      time->Wed Feb 28 04:33:35 2024
      type=AVC msg=audit(1709112815.429:356): avc:  denied  { read } for  pid=598 comm="systemd-journal" name="invocation:chronyd.service" dev="tmpfs" ino=17130 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=lnk_file permissive=1
      ----
      time->Wed Feb 28 04:37:17 2024
      type=AVC msg=audit(1709113037.362:419): avc:  denied  { read } for  pid=598 comm="systemd-journal" name="invocation:session-1.scope" dev="tmpfs" ino=23216 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 tclass=lnk_file permissive=1
       

      Please provide the package NVR for which bug is seen:

      selinux-policy-3.14.3-128.el8_9.1.noarch

      How reproducible:

      just once so far

      Steps to reproduce

      1. The problem appeared when we installed a new kernel and boot the machine again
      2.  
      3.  

      test logs: https://datawarehouse.cki-project.org/kcidb/tests/11492672

       

            rhn-support-zpytela Zdenek Pytela
            bgoncalv@redhat.com Bruno Goncalves
            Zdenek Pytela Zdenek Pytela
            SSG Security QE SSG Security QE
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: