Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-95689

selinux reports avc denied during installation of coreos-installer-bootinfra

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • selinux-policy-38.1.59-1.el9
    • No
    • Important
    • 1
    • rhel-security-selinux
    • ssg_security
    • 20
    • 1
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250716: 9
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • All
    • None

      What were you trying to do that didn't work?

      Install the coreos-installer-bootinfra package

      What is the impact of this issue to you?

      It is causing a failure during the coreos-installer CI in the osci.installability

      Please provide the package NVR for which the bug is seen:

      selinux-policy-targeted-38.1.57-1.el9.noarch

      How reproducible is this bug?:

      Install coreos-installer-bootinfra package on a rhel which contains selinux-policy-targeted version 38.1.57-1

      Steps to reproduce

      1. execute: 
        dnf install coreos-installer-bootinfra
      1. execute:  
        ausearch -m avc --raw | audit2why

        You should see:

      type=AVC msg=audit(1749151126.017:83): avc:  denied  { search } for  pid=4343 comm="coreos-installe" name="sss" dev="vda4" ino=1037 scontext=system_u:system_r:coreos_installer_t:s0 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=dir permissive=1

      Expected results

      Do not see an avc denied in the audit logs.

      Actual results

      type=AVC msg=audit(1749151126.017:83): avc:  denied  { search } for  pid=4343 comm="coreos-installe" name="sss" dev="vda4" ino=1037 scontext=system_u:system_r:coreos_installer_t:s0 tcontext=system_u:object_r:sssd_var_lib_t:s0 tclass=dir permissive=1

              rhn-support-zpytela Zdenek Pytela
              tbueno@redhat.com Tiago Bueno
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: