-
Story
-
Resolution: Done-Errata
-
Undefined
-
rhel-9.2.0
-
grafana-9.2.10-12.el9
-
None
-
rhel-sst-pt-pcp
-
ssg_platform_tools
-
10
-
14
-
None
-
QE ack
-
False
-
-
Yes
-
None
-
Pass
-
grafana-9.2.10-10.el9
-
None
-
Enhancement
-
-
Done
-
-
Unspecified
-
None
Description of problem:
grafana-server service runs as unconfined_service_t, which violates STIG, as STIG CIS server level 1 profile requires no service to run as "unconfined_service_t" SELinux type.
Version-Release number of selected component (if applicable):
grafana-9.0.9-2.el9
How reproducible:
Always
Steps to Reproduce:
1. Install grafana and start grafana-server service
- yum install -y grafana
- systemctl start grafana-server
2. Check if the grafana process runs as unconfined service type - ps -efZ | grep grafana-server
Actual results:
Grafana runs as unconfined service type:
- ps -efZ | grep grafana-server
system_u:system_r:unconfined_service_t:s0 grafana 40052 1 4 08:59 ? 00:00:00 /usr/sbin/grafana-server --config=/etc/grafana/grafana.ini --pidfile=/var/run/grafana/grafana-server.pid --packaging=rpm cfg:default.paths.logs=/var/log/grafana cfg:default.paths.data=/var/lib/grafana cfg:default.paths.plugins=/var/lib/grafana/plugins cfg:default.paths.provisioning=/etc/grafana/provisioning
Expected results:
Grafana does not run as unconfined service type
Additional info:
https://access.redhat.com/articles/2918071
- external trackers
- links to
-
RHBA-2023:124264 grafana bug fix and enhancement update
[RHEL-7505] grafana-server service runs as unconfined_service_t [rhel-9]
Resolution | New: Done-Errata [ 10803 ] | |
Status | Original: Release Pending [ 15735 ] | New: Closed [ 6 ] |
Release Date | New: 2024/04/30 |
Release Note Status | Original: In Progress [ 30960 ] | New: Done [ 30963 ] |
Release Note Text |
Original:
Feature, enhancement (describe the feature or enhancement from the userโs point of view):
A selinux policy for grafana has been introduced that installs when grafana is installed. Reason (why has the feature or enhancement been implemented): A selinux policy enhances security. Result (what is the current user experience): Prior to introducing this selinux policy, grafana-server runs as "unconfined_service_t". With the policy, grafana-server runs as grafana_t. |
New:
.A new `grafana-selinux` package
Previously, the default installation of `grafana-server` ran as an `unconfined_service_t` SELinux type. This update adds the new `grafana-selinux` package, which contains an SELinux policy for `grafana-server` and which is installed by default with `grafana-server`. As a result, `grafana-server` now runs as `grafana_t` SELinux type. |
Reset contact to default | Original: Watchers [ 32055 ] |
Release Note Status | New: In Progress [ 30960 ] |
Product Documentation Required | New: Yes [ 36650 ] |
Release Note Text |
Original:
Feature, enhancement (describe the feature or enhancement from the userโs point of view):
Reason (why has the feature or enhancement been implemented): Result (what is the current user experience): |
New:
Feature, enhancement (describe the feature or enhancement from the userโs point of view):
A selinux policy for grafana has been introduced that installs when grafana is installed. Reason (why has the feature or enhancement been implemented): A selinux policy enhances security. Result (what is the current user experience): Prior to introducing this selinux policy, grafana-server runs as "unconfined_service_t". With the policy, grafana-server runs as grafana_t. |
Release Note Text |
New:
Feature, enhancement (describe the feature or enhancement from the userโs point of view):
Reason (why has the feature or enhancement been implemented): Result (what is the current user experience): |
Docs Impact | Original: Unspecified [ 30765 ] | New: RN only [ 30768 ] |
Status | Original: Integration [ 18721 ] | New: Release Pending [ 15735 ] |
Fixed in Build | Original: grafana-9.2.10-11.el9 | New: grafana-9.2.10-12.el9 |
Target end | Original: 2023/11/27 | New: 2023/12/04 |
Link | New: This issue is related to ATTACH-9735 [ ATTACH-9735 ] |
Internal Target Milestone | Original: 13 [ 27962 ] | New: 14 [ 27963 ] |
Link | New: This issue is blocked by ENGCMP-3571 [ ENGCMP-3571 ] |
Fixed in Build | Original: grafana-9.2.10-10.el9 | New: grafana-9.2.10-11.el9 |
Status | Original: In Progress [ 10018 ] | New: Integration [ 18721 ] |
Remote Link |
New:
This issue links to " |
Errata Link | New: https://errata.devel.redhat.com/advisory/124264 |
Preliminary Testing | Original: Requested [ 34176 ] | New: Pass [ 34174 ] |
Preliminary Testing | Original: Pass [ 34174 ] | New: Requested [ 34176 ] |
Testable Builds | New: grafana-9.2.10-10.el9 |
Preliminary Testing | New: Pass [ 34174 ] |
Fixed in Build | New: grafana-9.2.10-10.el9 |
Remote Link | New: This issue links to "Test Requirement (BASEOS-18441) (Web Link)" [ 1474640 ] |
Status | Original: Planning [ 13521 ] | New: In Progress [ 10018 ] |
ACKs Check | New: QE ack [ 31163 ] |
Developer | New: Sam Feifer [ JIRAUSER215268 ] |
Target end | New: 2023/11/27 |
Internal Target Milestone | New: 13 [ 27962 ] |
Internal Target Milestone numeric | Original: 42 | New: 57005 |
Internal Target Milestone numeric | New: 42 |
Sub-System Group | New: ssg_platform_tools [ 27796 ] |
Reset contact to default | Original: Assignee,Qa Contact,Doc Contact,Pool Team,Watchers,Developer [ 32051, 32052, 32053, 32054, 32055, 32850 ] | New: Watchers [ 32055 ] |
Dev Target Milestone | New: 10 [ 16975 ] | |
Fix Version/s | New: rhel-9.4.0 [ 12407281 ] | |
Release Note Type | Original: If docs needed, set a value [ 31859 ] | New: Enhancement [ 30953 ] |
Assignee | Original: grafana-maint [ grafana-maint ] | New: Sam Feifer [ rh-ee-sfeifer ] |
Issue Type | Original: Bug [ 1 ] | New: Story [ 17 ] |
Labels | Original: Unset | New: FutureFeature MigratedToJIRA Triaged |
Status | Original: New [ 10016 ] | New: Planning [ 13521 ] |
Component/s | Original: grafana [ 12381197 ] |
Remote Link | New: This issue links to "Red Hat Issue Tracker RHELPLAN-156890 (Web Link)" [ 1404650 ] |
Remote Link | New: This issue links to "CEE GitLab toolchain-qe/tests/grafana/-/tree/master/Sanity/selinux-unconfined (Web Link)" [ 1404651 ] |
Issue Type | Original: Bug [ 1 ] | New: Story [ 17 ] |
Labels | Original: Unset | New: FutureFeature MigratedToJIRA Triaged |
Component/s | New: grafana [ 12381197 ] |
Since the problem described in this issue should be resolved in a recent advisory, it has been closed.
For information on the advisory (grafana bug fix and enhancement update), and where to find the updated files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHBA-2024:2205