-
Bug
-
Resolution: Unresolved
-
Normal
-
rhel-10.0.beta
-
No
-
None
-
rhel-sst-security-selinux
-
ssg_security
-
1
-
QE ack
-
False
-
-
No
-
None
-
-
None
-
None
-
Unspecified Release Note Type - Unknown
-
None
Building a disk image with livemedia-creator produces the following avc denials (likely limited to ppc64le and aarch64, untested on s390x, not seen on x86_64):
aarch64:
time->Fri Sep 13 12:46:11 2024 type=PROCTITLE msg=audit(1726245971.221:731): proctitle=67726F7570616464002D66002D6700313134002D7200706F6C6B697464 type=SYSCALL msg=audit(1726245971.221:731): arch=c00000b7 syscall=56 success=no exit=-13 a0=ffffffffffffff9c a1=aaaabd570680 a2=88902 a3=0 items=0 ppid=8258 pid=8260 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="groupadd" exe="/usr/sbin/groupadd" subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1726245971.221:731): avc: denied { write } for pid=8260 comm="groupadd" name="group" dev="dm-5" ino=21649 scontext=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file permissive=0 ---- time->Fri Sep 13 12:46:35 2024 type=PROCTITLE msg=audit(1726245995.031:735): proctitle=67726F7570616464002D720073737364 type=SYSCALL msg=audit(1726245995.031:735): arch=c00000b7 syscall=56 success=no exit=-13 a0=ffffffffffffff9c a1=aaaab5140680 a2=88902 a3=0 items=0 ppid=8358 pid=8360 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="groupadd" exe="/usr/sbin/groupadd" subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1726245995.031:735): avc: denied { write } for pid=8360 comm="groupadd" name="group" dev="dm-5" ino=21649 scontext=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file permissive=0
ppc64le:
time->Fri Sep 13 13:09:37 2024 type=PROCTITLE msg=audit(1726247377.094:698): proctitle=67726F7570616464002D66002D6700313134002D7200706F6C6B697464 type=SYSCALL msg=audit(1726247377.094:698): arch=c0000015 syscall=286 success=no exit=-13 a0=ffffffffffffff9c a1=1159a0680 a2=88902 a3=0 items=0 ppid=7463 pid=7465 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="groupadd" exe="/usr/sbin/groupadd" subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1726247377.094:698): avc: denied { write } for pid=7465 comm="groupadd" name="group" dev="dm-5" ino=23082 scontext=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file permissive=0 ---- time->Fri Sep 13 13:09:56 2024 type=PROCTITLE msg=audit(1726247396.773:702): proctitle=67726F7570616464002D720073737364 type=SYSCALL msg=audit(1726247396.773:702): arch=c0000015 syscall=286 success=no exit=-13 a0=ffffffffffffff9c a1=135160680 a2=88902 a3=0 items=0 ppid=7557 pid=7559 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="groupadd" exe="/usr/sbin/groupadd" subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(1726247396.773:702): avc: denied { write } for pid=7559 comm="groupadd" name="group" dev="dm-5" ino=23082 scontext=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:etc_t:s0 tclass=file permissive=0
Observed on RHEL-10.0-20240901.1 with selinux-policy-40.13.9-1.el10.noarch, lorax-40.5.6-1.el10.s390x, anaconda-40.22.3.12-1.el10.s390x.
Steps to reproduce:
- Install lorax package, download a RHEL-10 boot.iso, prepare a kickstart file for livemedia-creator (you can use the attached one).
- Try to create a disk image using livemedia-creator:
livemedia-creator --make-disk --no-virt --iso boot.iso --ks ks.cfg --nomacboot