Re: Help with test failures

Zdenek Pytela <[email protected]> Thu, 6 Jun 2024 18:17:08 +0200
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <CAO4UijD7FPVQTOyrViu6DSy4zG7q8o7UDxuJ6e31QLrTwinkgA@mail.gmail.com>
--===============2803376953478871099==
Content-Type: multipart/alternative; boundary="0000000000006e4a99061a3b0451"

--0000000000006e4a99061a3b0451
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Thu, May 30, 2024 at 12:14=E2=80=AFAM Orion Poplawski <[email protected]> w=
rote:

> We have the following PR for zabbix SELinux policy:
>
> https://src.fedoraproject.org/rpms/zabbix/pull-request/10
>
> and we're getting some test failures, but I can't really interpret them.
>
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
> ::   Unsound/dangerous policy practices
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
>
> :: [ 21:15:26 ] :: [  BEGIN   ] :: Running 'semodule -lfull | grep zabbix=
'
> :: [ 21:15:26 ] :: [   PASS   ] :: Command 'semodule -lfull | grep zabbix=
'
> (Expected 0, got 0)
> :: [ 21:15:26 ] :: [  BEGIN   ] :: Running 'semodule -X 200 --cil -E
> zabbix'
> :: [ 21:15:26 ] :: [   PASS   ] :: Command 'semodule -X 200 --cil -E
> zabbix'
> (Expected 0, got 0)
> :: [ 21:15:26 ] :: [  BEGIN   ] :: Running 'python3 test.py zabbix.cil
> policy/zabbix.te'
> /var/str/DSP_test/test.py:64: SyntaxWarning: invalid escape sequence '\('
>   out =3D subprocess.run(['grep', '-E', '[A-Za-z_]+\(.*\)', te_source_fil=
e],
> capture_output=3DTrue, text=3DTrue)
> :: [ 21:15:27 ] :: [   FAIL   ] :: Command 'python3 test.py zabbix.cil
> policy/zabbix.te' (Expected 0, got 4)
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
> ::   Duration: 1s
> ::   Assertions: 2 good, 1 bad
> ::   RESULT: FAIL (Unsound/dangerous policy practices)
>
> This seems like it might be a python error in the test.
>
>
>
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
> ::   SELint static analysis
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
>
> :: [ 21:15:27 ] :: [  BEGIN   ] :: Running 'selint -s -r -d E-005 -d W-00=
4
> -d
> W-005 -d W-010 -d S-001 -d S-010  --context=3Dbase-policy policy/zabbix.f=
c
> policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny'
> :: [ 21:15:27 ] :: [   PASS   ] :: Command 'selint -s -r -d E-005 -d W-00=
4
> -d
> W-005 -d W-010 -d S-001 -d S-010  --context=3Dbase-policy policy/zabbix.f=
c
> policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny' (Expected 0, got 0)
> :: [ 21:15:27 ] :: [  BEGIN   ] :: Running 'grep -v 'F-002'
> '/tmp/tmp.DVGZL996ny''
> :: [ 21:15:27 ] :: [   FAIL   ] :: Command 'grep -v 'F-002'
> '/tmp/tmp.DVGZL996ny'' (Expected 1, got 0)
>
> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::::
> ::   Duration: 0s
> ::   Assertions: 1 good, 1 bad
> ::   RESULT: FAIL (SELint static analysis)
>
> No idea about this.
>
>
> In the installability teest:
>
> BAD install: zabbix-1:6.0.30-1.fc41.x86_64 (selinux AVCs)
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.247:957) : avc:  denied  { map=
_read
> map_write } for  pid=3D4601 comm=3Dselinux-autorel
> scontext=3Dsystem_u:system_r:selinux_autorelabel_generator_t:s0
> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.254:958) : avc:  denied  { map=
_read
> map_write } for  pid=3D4605 comm=3Dsystemd-fstab-g
> scontext=3Dsystem_u:system_r:systemd_fstab_generator_t:s0
> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.261:959) : avc:  denied  { map=
_read
> map_write } for  pid=3D4609 comm=3Dsystemd-gpt-aut
> scontext=3Dsystem_u:system_r:systemd_gpt_generator_t:s0
> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.273:960) : avc:  denied  { map=
_read
> map_write } for  pid=3D4613 comm=3Dsystemd-rc-loca
> scontext=3Dsystem_u:system_r:systemd_rc_local_generator_t:s0
> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.281:961) : avc:  denied  { rea=
d }
> for
> pid=3D4615 comm=3Dsystemd-ssh-gen name=3Dvsock dev=3D"devtmpfs" ino=3D388
> scontext=3Dsystem_u:system_r:init_t:s0
> tcontext=3Dsystem_u:object_r:vsock_device_t:s0 tclass=3Dchr_file permissi=
ve=3D0
> ----
> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.284:962) : avc:  denied  { map=
_read
> map_write } for  pid=3D4619 comm=3Dsystemd-sysv-ge
> scontext=3Dsystem_u:system_r:systemd_sysv_generator_t:s0
> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0
>
>
> and more, but these seem unrelated to the zabbix package.
>
Hi Orion,

commenting only on the second part:
bpf map_read/map_write is a known issue which has been fixed in systemd,
using vsock is a feature of ssh generator, new in systemd v256, which was
fixed in policy 2 builds ago.
Please update your system.


>
>
> --
> Orion Poplawski
> he/him/his  - surely the least important thing about me
> Manager of IT Systems                      720-772-5637
> NWRA, Boulder/CoRA Office             FAX: 303-415-9702
> 3380 Mitchell Lane                       [email protected]
> Boulder, CO 80301                 https://www.nwra.com/
> --
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedoraproject.org/archives/list/[email protected]=
.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>


--=20

Zdenek Pytela
Security SELinux team

--0000000000006e4a99061a3b0451
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">=
<div dir=3D"ltr" class=3D"gmail_attr">On Thu, May 30, 2024 at 12:14=E2=80=
=AFAM Orion Poplawski &lt;<a href=3D"mailto:[email protected]">[email protected]<=
/a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">W=
e have the following PR for zabbix SELinux policy:<br>
<br>
<a href=3D"https://src.fedoraproject.org/rpms/zabbix/pull-request/10" rel=
=3D"noreferrer" target=3D"_blank">https://src.fedoraproject.org/rpms/zabbix=
/pull-request/10</a><br>
<br>
and we&#39;re getting some test failures, but I can&#39;t really interpret =
them.<br>
<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
::=C2=A0 =C2=A0Unsound/dangerous policy practices<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
<br>
:: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running &#39;semodule -lf=
ull | grep zabbix&#39;<br>
:: [ 21:15:26 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command &#39;semodul=
e -lfull | grep zabbix&#39;<br>
(Expected 0, got 0)<br>
:: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running &#39;semodule -X =
200 --cil -E zabbix&#39;<br>
:: [ 21:15:26 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command &#39;semodul=
e -X 200 --cil -E zabbix&#39;<br>
(Expected 0, got 0)<br>
:: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running &#39;python3 test=
.py zabbix.cil<br>
policy/zabbix.te&#39;<br>
/var/str/DSP_test/test.py:64: SyntaxWarning: invalid escape sequence &#39;\=
(&#39;<br>
=C2=A0 out =3D subprocess.run([&#39;grep&#39;, &#39;-E&#39;, &#39;[A-Za-z_]=
+\(.*\)&#39;, te_source_file],<br>
capture_output=3DTrue, text=3DTrue)<br>
:: [ 21:15:27 ] :: [=C2=A0 =C2=A0FAIL=C2=A0 =C2=A0] :: Command &#39;python3=
 test.py zabbix.cil<br>
policy/zabbix.te&#39; (Expected 0, got 4)<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
::=C2=A0 =C2=A0Duration: 1s<br>
::=C2=A0 =C2=A0Assertions: 2 good, 1 bad<br>
::=C2=A0 =C2=A0RESULT: FAIL (Unsound/dangerous policy practices)<br>
<br>
This seems like it might be a python error in the test.<br>
<br>
<br>
<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
::=C2=A0 =C2=A0SELint static analysis<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
<br>
:: [ 21:15:27 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running &#39;selint -s -r=
 -d E-005 -d W-004 -d<br>
W-005 -d W-010 -d S-001 -d S-010=C2=A0 --context=3Dbase-policy policy/zabbi=
x.fc<br>
policy/zabbix.te 2&gt;&amp;1 | tee /tmp/tmp.DVGZL996ny&#39;<br>
:: [ 21:15:27 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command &#39;selint =
-s -r -d E-005 -d W-004 -d<br>
W-005 -d W-010 -d S-001 -d S-010=C2=A0 --context=3Dbase-policy policy/zabbi=
x.fc<br>
policy/zabbix.te 2&gt;&amp;1 | tee /tmp/tmp.DVGZL996ny&#39; (Expected 0, go=
t 0)<br>
:: [ 21:15:27 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running &#39;grep -v &#39=
;F-002&#39; &#39;/tmp/tmp.DVGZL996ny&#39;&#39;<br>
:: [ 21:15:27 ] :: [=C2=A0 =C2=A0FAIL=C2=A0 =C2=A0] :: Command &#39;grep -v=
 &#39;F-002&#39;<br>
&#39;/tmp/tmp.DVGZL996ny&#39;&#39; (Expected 1, got 0)<br>
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::=
:::::<br>
::=C2=A0 =C2=A0Duration: 0s<br>
::=C2=A0 =C2=A0Assertions: 1 good, 1 bad<br>
::=C2=A0 =C2=A0RESULT: FAIL (SELint static analysis)<br>
<br>
No idea about this.<br>
<br>
<br>
In the installability teest:<br>
<br>
BAD install: zabbix-1:6.0.30-1.fc41.x86_64 (selinux AVCs)<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.247:957) : avc:=C2=A0 denied=C2=
=A0 { map_read<br>
map_write } for=C2=A0 pid=3D4601 comm=3Dselinux-autorel<br>
scontext=3Dsystem_u:system_r:selinux_autorelabel_generator_t:s0<br>
tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.254:958) : avc:=C2=A0 denied=C2=
=A0 { map_read<br>
map_write } for=C2=A0 pid=3D4605 comm=3Dsystemd-fstab-g<br>
scontext=3Dsystem_u:system_r:systemd_fstab_generator_t:s0<br>
tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.261:959) : avc:=C2=A0 denied=C2=
=A0 { map_read<br>
map_write } for=C2=A0 pid=3D4609 comm=3Dsystemd-gpt-aut<br>
scontext=3Dsystem_u:system_r:systemd_gpt_generator_t:s0<br>
tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.273:960) : avc:=C2=A0 denied=C2=
=A0 { map_read<br>
map_write } for=C2=A0 pid=3D4613 comm=3Dsystemd-rc-loca<br>
scontext=3Dsystem_u:system_r:systemd_rc_local_generator_t:s0<br>
tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.281:961) : avc:=C2=A0 denied=C2=
=A0 { read } for<br>
pid=3D4615 comm=3Dsystemd-ssh-gen name=3Dvsock dev=3D&quot;devtmpfs&quot; i=
no=3D388<br>
scontext=3Dsystem_u:system_r:init_t:s0<br>
tcontext=3Dsystem_u:object_r:vsock_device_t:s0 tclass=3Dchr_file permissive=
=3D0<br>
----<br>
type=3DAVC msg=3Daudit(05/28/2024 21:15:28.284:962) : avc:=C2=A0 denied=C2=
=A0 { map_read<br>
map_write } for=C2=A0 pid=3D4619 comm=3Dsystemd-sysv-ge<br>
scontext=3Dsystem_u:system_r:systemd_sysv_generator_t:s0<br>
tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br>
<br>
<br>
and more, but these seem unrelated to the zabbix package.<br></blockquote><=
div>Hi Orion,</div><div><br></div><div>commenting only on the second part:=
=C2=A0</div><div>bpf map_read/map_write is a known issue which has been fix=
ed in systemd,<br></div><div>using vsock is a feature of ssh generator, new=
 in systemd v256, which was fixed in policy 2 builds ago.</div><div>Please =
update your system.</div><div><br></div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pad=
ding-left:1ex">
<br>
<br>
<br>
-- <br>
Orion Poplawski<br>
he/him/his=C2=A0 - surely the least important thing about me<br>
Manager of IT Systems=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=
=A0 =C2=A0 =C2=A0 =C2=A0 720-772-5637<br>
NWRA, Boulder/CoRA Office=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0FA=
X: 303-415-9702<br>
3380 Mitchell Lane=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"mailto:[email protected]" target=3D"_bla=
nk">[email protected]</a><br>
Boulder, CO 80301=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =
=C2=A0<a href=3D"https://www.nwra.com/" rel=3D"noreferrer" target=3D"_blank=
">https://www.nwra.com/</a><br>
--<br>
_______________________________________________<br>
selinux mailing list -- <a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]=
aproject.org" target=3D"_blank">[email protected]</a><b=
r>
Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro=
ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe=
doraproject.org/en-US/project/code-of-conduct/</a><br>
List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui=
delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik=
i/Mailing_list_guidelines</a><br>
List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel=
[email protected]" rel=3D"noreferrer" target=3D"_blank">https://=
lists.fedoraproject.org/archives/list/[email protected]</a><b=
r>
Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras=
tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/=
fedora-infrastructure/new_issue</a><br>
</blockquote></div><br clear=3D"all"><br><span class=3D"gmail_signature_pre=
fix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"l=
tr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div>=
<div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br>
Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>=
</div></div></div></div></div></div></div></div></div></div></div></div>

--0000000000006e4a99061a3b0451--

--===============2803376953478871099==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2VsaW51
eCBtYWlsaW5nIGxpc3QgLS0gc2VsaW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpUbyB1bnN1
YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRvIHNlbGludXgtbGVhdmVAbGlzdHMuZmVkb3JhcHJvamVj
dC5vcmcKRmVkb3JhIENvZGUgb2YgQ29uZHVjdDogaHR0cHM6Ly9kb2NzLmZlZG9yYXByb2plY3Qu
b3JnL2VuLVVTL3Byb2plY3QvY29kZS1vZi1jb25kdWN0LwpMaXN0IEd1aWRlbGluZXM6IGh0dHBz
Oi8vZmVkb3JhcHJvamVjdC5vcmcvd2lraS9NYWlsaW5nX2xpc3RfZ3VpZGVsaW5lcwpMaXN0IEFy
Y2hpdmVzOiBodHRwczovL2xpc3RzLmZlZG9yYXByb2plY3Qub3JnL2FyY2hpdmVzL2xpc3Qvc2Vs
aW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpEbyBub3QgcmVwbHkgdG8gc3BhbSwgcmVwb3J0
IGl0OiBodHRwczovL3BhZ3VyZS5pby9mZWRvcmEtaW5mcmFzdHJ1Y3R1cmUvbmV3X2lzc3VlCg==

--===============2803376953478871099==--