Re: Help with test failures
Zdenek Pytela <[email protected]> Thu, 6 Jun 2024 18:17:08 +0200
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CAO4UijD7FPVQTOyrViu6DSy4zG7q8o7UDxuJ6e31QLrTwinkgA@mail.gmail.com> |
--===============2803376953478871099== Content-Type: multipart/alternative; boundary="0000000000006e4a99061a3b0451" --0000000000006e4a99061a3b0451 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, May 30, 2024 at 12:14=E2=80=AFAM Orion Poplawski <[email protected]> w= rote: > We have the following PR for zabbix SELinux policy: > > https://src.fedoraproject.org/rpms/zabbix/pull-request/10 > > and we're getting some test failures, but I can't really interpret them. > > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > :: Unsound/dangerous policy practices > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > > :: [ 21:15:26 ] :: [ BEGIN ] :: Running 'semodule -lfull | grep zabbix= ' > :: [ 21:15:26 ] :: [ PASS ] :: Command 'semodule -lfull | grep zabbix= ' > (Expected 0, got 0) > :: [ 21:15:26 ] :: [ BEGIN ] :: Running 'semodule -X 200 --cil -E > zabbix' > :: [ 21:15:26 ] :: [ PASS ] :: Command 'semodule -X 200 --cil -E > zabbix' > (Expected 0, got 0) > :: [ 21:15:26 ] :: [ BEGIN ] :: Running 'python3 test.py zabbix.cil > policy/zabbix.te' > /var/str/DSP_test/test.py:64: SyntaxWarning: invalid escape sequence '\(' > out =3D subprocess.run(['grep', '-E', '[A-Za-z_]+\(.*\)', te_source_fil= e], > capture_output=3DTrue, text=3DTrue) > :: [ 21:15:27 ] :: [ FAIL ] :: Command 'python3 test.py zabbix.cil > policy/zabbix.te' (Expected 0, got 4) > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > :: Duration: 1s > :: Assertions: 2 good, 1 bad > :: RESULT: FAIL (Unsound/dangerous policy practices) > > This seems like it might be a python error in the test. > > > > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > :: SELint static analysis > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > > :: [ 21:15:27 ] :: [ BEGIN ] :: Running 'selint -s -r -d E-005 -d W-00= 4 > -d > W-005 -d W-010 -d S-001 -d S-010 --context=3Dbase-policy policy/zabbix.f= c > policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny' > :: [ 21:15:27 ] :: [ PASS ] :: Command 'selint -s -r -d E-005 -d W-00= 4 > -d > W-005 -d W-010 -d S-001 -d S-010 --context=3Dbase-policy policy/zabbix.f= c > policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny' (Expected 0, got 0) > :: [ 21:15:27 ] :: [ BEGIN ] :: Running 'grep -v 'F-002' > '/tmp/tmp.DVGZL996ny'' > :: [ 21:15:27 ] :: [ FAIL ] :: Command 'grep -v 'F-002' > '/tmp/tmp.DVGZL996ny'' (Expected 1, got 0) > > :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= ::::::: > :: Duration: 0s > :: Assertions: 1 good, 1 bad > :: RESULT: FAIL (SELint static analysis) > > No idea about this. > > > In the installability teest: > > BAD install: zabbix-1:6.0.30-1.fc41.x86_64 (selinux AVCs) > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.247:957) : avc: denied { map= _read > map_write } for pid=3D4601 comm=3Dselinux-autorel > scontext=3Dsystem_u:system_r:selinux_autorelabel_generator_t:s0 > tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0 > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.254:958) : avc: denied { map= _read > map_write } for pid=3D4605 comm=3Dsystemd-fstab-g > scontext=3Dsystem_u:system_r:systemd_fstab_generator_t:s0 > tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0 > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.261:959) : avc: denied { map= _read > map_write } for pid=3D4609 comm=3Dsystemd-gpt-aut > scontext=3Dsystem_u:system_r:systemd_gpt_generator_t:s0 > tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0 > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.273:960) : avc: denied { map= _read > map_write } for pid=3D4613 comm=3Dsystemd-rc-loca > scontext=3Dsystem_u:system_r:systemd_rc_local_generator_t:s0 > tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0 > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.281:961) : avc: denied { rea= d } > for > pid=3D4615 comm=3Dsystemd-ssh-gen name=3Dvsock dev=3D"devtmpfs" ino=3D388 > scontext=3Dsystem_u:system_r:init_t:s0 > tcontext=3Dsystem_u:object_r:vsock_device_t:s0 tclass=3Dchr_file permissi= ve=3D0 > ---- > type=3DAVC msg=3Daudit(05/28/2024 21:15:28.284:962) : avc: denied { map= _read > map_write } for pid=3D4619 comm=3Dsystemd-sysv-ge > scontext=3Dsystem_u:system_r:systemd_sysv_generator_t:s0 > tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0 > > > and more, but these seem unrelated to the zabbix package. > Hi Orion, commenting only on the second part: bpf map_read/map_write is a known issue which has been fixed in systemd, using vsock is a feature of ssh generator, new in systemd v256, which was fixed in policy 2 builds ago. Please update your system. > > > -- > Orion Poplawski > he/him/his - surely the least important thing about me > Manager of IT Systems 720-772-5637 > NWRA, Boulder/CoRA Office FAX: 303-415-9702 > 3380 Mitchell Lane [email protected] > Boulder, CO 80301 https://www.nwra.com/ > -- > _______________________________________________ > selinux mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/[email protected]= .org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue > --=20 Zdenek Pytela Security SELinux team --0000000000006e4a99061a3b0451 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote">= <div dir=3D"ltr" class=3D"gmail_attr">On Thu, May 30, 2024 at 12:14=E2=80= =AFAM Orion Poplawski <<a href=3D"mailto:[email protected]">[email protected]<= /a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0= px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">W= e have the following PR for zabbix SELinux policy:<br> <br> <a href=3D"https://src.fedoraproject.org/rpms/zabbix/pull-request/10" rel= =3D"noreferrer" target=3D"_blank">https://src.fedoraproject.org/rpms/zabbix= /pull-request/10</a><br> <br> and we're getting some test failures, but I can't really interpret = them.<br> <br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> ::=C2=A0 =C2=A0Unsound/dangerous policy practices<br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> <br> :: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running 'semodule -lf= ull | grep zabbix'<br> :: [ 21:15:26 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command 'semodul= e -lfull | grep zabbix'<br> (Expected 0, got 0)<br> :: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running 'semodule -X = 200 --cil -E zabbix'<br> :: [ 21:15:26 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command 'semodul= e -X 200 --cil -E zabbix'<br> (Expected 0, got 0)<br> :: [ 21:15:26 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running 'python3 test= .py zabbix.cil<br> policy/zabbix.te'<br> /var/str/DSP_test/test.py:64: SyntaxWarning: invalid escape sequence '\= ('<br> =C2=A0 out =3D subprocess.run(['grep', '-E', '[A-Za-z_]= +\(.*\)', te_source_file],<br> capture_output=3DTrue, text=3DTrue)<br> :: [ 21:15:27 ] :: [=C2=A0 =C2=A0FAIL=C2=A0 =C2=A0] :: Command 'python3= test.py zabbix.cil<br> policy/zabbix.te' (Expected 0, got 4)<br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> ::=C2=A0 =C2=A0Duration: 1s<br> ::=C2=A0 =C2=A0Assertions: 2 good, 1 bad<br> ::=C2=A0 =C2=A0RESULT: FAIL (Unsound/dangerous policy practices)<br> <br> This seems like it might be a python error in the test.<br> <br> <br> <br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> ::=C2=A0 =C2=A0SELint static analysis<br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> <br> :: [ 21:15:27 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running 'selint -s -r= -d E-005 -d W-004 -d<br> W-005 -d W-010 -d S-001 -d S-010=C2=A0 --context=3Dbase-policy policy/zabbi= x.fc<br> policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny'<br> :: [ 21:15:27 ] :: [=C2=A0 =C2=A0PASS=C2=A0 =C2=A0] :: Command 'selint = -s -r -d E-005 -d W-004 -d<br> W-005 -d W-010 -d S-001 -d S-010=C2=A0 --context=3Dbase-policy policy/zabbi= x.fc<br> policy/zabbix.te 2>&1 | tee /tmp/tmp.DVGZL996ny' (Expected 0, go= t 0)<br> :: [ 21:15:27 ] :: [=C2=A0 BEGIN=C2=A0 =C2=A0] :: Running 'grep -v '= ;F-002' '/tmp/tmp.DVGZL996ny''<br> :: [ 21:15:27 ] :: [=C2=A0 =C2=A0FAIL=C2=A0 =C2=A0] :: Command 'grep -v= 'F-002'<br> '/tmp/tmp.DVGZL996ny'' (Expected 1, got 0)<br> :::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::= :::::<br> ::=C2=A0 =C2=A0Duration: 0s<br> ::=C2=A0 =C2=A0Assertions: 1 good, 1 bad<br> ::=C2=A0 =C2=A0RESULT: FAIL (SELint static analysis)<br> <br> No idea about this.<br> <br> <br> In the installability teest:<br> <br> BAD install: zabbix-1:6.0.30-1.fc41.x86_64 (selinux AVCs)<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.247:957) : avc:=C2=A0 denied=C2= =A0 { map_read<br> map_write } for=C2=A0 pid=3D4601 comm=3Dselinux-autorel<br> scontext=3Dsystem_u:system_r:selinux_autorelabel_generator_t:s0<br> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.254:958) : avc:=C2=A0 denied=C2= =A0 { map_read<br> map_write } for=C2=A0 pid=3D4605 comm=3Dsystemd-fstab-g<br> scontext=3Dsystem_u:system_r:systemd_fstab_generator_t:s0<br> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.261:959) : avc:=C2=A0 denied=C2= =A0 { map_read<br> map_write } for=C2=A0 pid=3D4609 comm=3Dsystemd-gpt-aut<br> scontext=3Dsystem_u:system_r:systemd_gpt_generator_t:s0<br> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.273:960) : avc:=C2=A0 denied=C2= =A0 { map_read<br> map_write } for=C2=A0 pid=3D4613 comm=3Dsystemd-rc-loca<br> scontext=3Dsystem_u:system_r:systemd_rc_local_generator_t:s0<br> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.281:961) : avc:=C2=A0 denied=C2= =A0 { read } for<br> pid=3D4615 comm=3Dsystemd-ssh-gen name=3Dvsock dev=3D"devtmpfs" i= no=3D388<br> scontext=3Dsystem_u:system_r:init_t:s0<br> tcontext=3Dsystem_u:object_r:vsock_device_t:s0 tclass=3Dchr_file permissive= =3D0<br> ----<br> type=3DAVC msg=3Daudit(05/28/2024 21:15:28.284:962) : avc:=C2=A0 denied=C2= =A0 { map_read<br> map_write } for=C2=A0 pid=3D4619 comm=3Dsystemd-sysv-ge<br> scontext=3Dsystem_u:system_r:systemd_sysv_generator_t:s0<br> tcontext=3Dsystem_u:system_r:init_t:s0 tclass=3Dbpf permissive=3D0<br> <br> <br> and more, but these seem unrelated to the zabbix package.<br></blockquote><= div>Hi Orion,</div><div><br></div><div>commenting only on the second part:= =C2=A0</div><div>bpf map_read/map_write is a known issue which has been fix= ed in systemd,<br></div><div>using vsock is a feature of ssh generator, new= in systemd v256, which was fixed in policy 2 builds ago.</div><div>Please = update your system.</div><div><br></div><blockquote class=3D"gmail_quote" s= tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pad= ding-left:1ex"> <br> <br> <br> -- <br> Orion Poplawski<br> he/him/his=C2=A0 - surely the least important thing about me<br> Manager of IT Systems=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2= =A0 =C2=A0 =C2=A0 =C2=A0 720-772-5637<br> NWRA, Boulder/CoRA Office=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0FA= X: 303-415-9702<br> 3380 Mitchell Lane=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"mailto:[email protected]" target=3D"_bla= nk">[email protected]</a><br> Boulder, CO 80301=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 = =C2=A0<a href=3D"https://www.nwra.com/" rel=3D"noreferrer" target=3D"_blank= ">https://www.nwra.com/</a><br> --<br> _______________________________________________<br> selinux mailing list -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]= aproject.org" target=3D"_blank">[email protected]</a><b= r> Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro= ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe= doraproject.org/en-US/project/code-of-conduct/</a><br> List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui= delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik= i/Mailing_list_guidelines</a><br> List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel= [email protected]" rel=3D"noreferrer" target=3D"_blank">https://= lists.fedoraproject.org/archives/list/[email protected]</a><b= r> Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras= tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/= fedora-infrastructure/new_issue</a><br> </blockquote></div><br clear=3D"all"><br><span class=3D"gmail_signature_pre= fix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><div dir=3D"l= tr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div>= <div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br> Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>= </div></div></div></div></div></div></div></div></div></div></div></div> --0000000000006e4a99061a3b0451-- --===============2803376953478871099== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0KX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kc2VsaW51 eCBtYWlsaW5nIGxpc3QgLS0gc2VsaW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpUbyB1bnN1 YnNjcmliZSBzZW5kIGFuIGVtYWlsIHRvIHNlbGludXgtbGVhdmVAbGlzdHMuZmVkb3JhcHJvamVj dC5vcmcKRmVkb3JhIENvZGUgb2YgQ29uZHVjdDogaHR0cHM6Ly9kb2NzLmZlZG9yYXByb2plY3Qu b3JnL2VuLVVTL3Byb2plY3QvY29kZS1vZi1jb25kdWN0LwpMaXN0IEd1aWRlbGluZXM6IGh0dHBz Oi8vZmVkb3JhcHJvamVjdC5vcmcvd2lraS9NYWlsaW5nX2xpc3RfZ3VpZGVsaW5lcwpMaXN0IEFy Y2hpdmVzOiBodHRwczovL2xpc3RzLmZlZG9yYXByb2plY3Qub3JnL2FyY2hpdmVzL2xpc3Qvc2Vs aW51eEBsaXN0cy5mZWRvcmFwcm9qZWN0Lm9yZwpEbyBub3QgcmVwbHkgdG8gc3BhbSwgcmVwb3J0 IGl0OiBodHRwczovL3BhZ3VyZS5pby9mZWRvcmEtaW5mcmFzdHJ1Y3R1cmUvbmV3X2lzc3VlCg== --===============2803376953478871099==--