Uploaded image for project: 'RHEL Testing'
  1. RHEL Testing
  2. RHELTEST-2512

misc/reboot-test: avc denial during reboot test

XMLWordPrintable

    • False
    • Hide

      None

      Show
      None
    • False
    • None
    • rhel-se-kernel

      ocurred on 9.0 with debug kernel on CKI testing:

      https://datawarehouse.cki-project.org/kcidb/tests/redhat:2273996893_x86_64_kernel-debug_kcidb_tool_20485138_30

      SELinux status:                 enabled
      SELinuxfs mount:                /sys/fs/selinux
      SELinux root directory:         /etc/selinux
      Loaded policy name:             targeted
      Current mode:                   permissive
      Mode from config file:          permissive
      Policy MLS status:              enabled
      Policy deny_unknown status:     allowed
      Memory protection checking:     actual (secure)
      Max kernel policy version:      33
      selinux-policy-34.1.29-1.el9_0.3.noarch
      ----
      time->Wed Jan 21 01:12:05 2026
      type=USER_AVC msg=audit(1768957925.268:307170): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  denied  { start } for auid=n/a uid=0 gid=0 path="/usr/lib/systemd/system/reboot.target" cmdline="" function="bus_unit_method_start_generic" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:object_r:power_unit_file_t:s0 tclass=service permissive=0  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
      ----
      time->Wed Jan 21 01:12:05 2026
      type=USER_AVC msg=audit(1768957925.269:307171): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  denied  { start } for auid=n/a uid=0 gid=0 path="/usr/lib/systemd/system/reboot.target" cmdline="" function="bus_unit_queue_job" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:object_r:power_unit_file_t:s0 tclass=service permissive=0  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
      ----
      time->Wed Jan 21 01:12:05 2026
      type=USER_AVC msg=audit(1768957925.280:307172): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  denied  { status } for auid=n/a uid=0 gid=0 path="/usr/lib/systemd/system/reboot.target" cmdline="" function="reply_unit_path" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:object_r:power_unit_file_t:s0 tclass=service permissive=0  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
      ----
      time->Wed Jan 21 01:12:05 2026
      type=USER_AVC msg=audit(1768957925.529:307184): pid=1 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:init_t:s0 msg='avc:  denied  { status } for auid=n/a uid=0 gid=0 path="/usr/lib/systemd/system/reboot.target" cmdline="" function="mac_selinux_filter" scontext=system_u:system_r:unconfined_service_t:s0 tcontext=system_u:object_r:power_unit_file_t:s0 tclass=service permissive=0  exe="/usr/lib/systemd/systemd" sauid=0 hostname=? addr=? terminal=?'
       

      This was already during reboot test. The timeline of the error suggests epoch 1768957925 which on console is close to this audit message, but far (10s) from when restraintd initiates

      the reboot:

        [26689.185287] restraintd[4192]: ** Running task: 210672218 [Reboot test]                                                                        
      ...
        [26700.420169] audit: type=1305 audit(1768957926.265:307199): op=set audit_pid=0 old=3346 auid=4294967295 ses=4294967295                           
        subj=system_u:system_r:auditd_t:s0 res=1    

      Its unclear what service tried this.

              Unassigned Unassigned
              rhn-support-rbergant Roberto Bergantinos Corpas
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: