Re: Fixing denials

Zdenek Pytela via selinux <[email protected]> Thu, 16 Jan 2025 13:27:51 +0100
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <CAO4UijDs6PCff44kGo_4g7abe2bRXUhNdZ6hUDx2Q=wBMgDu+w@mail.gmail.com>
--===============9214125785334939515==
Content-Type: multipart/alternative; boundary="000000000000ddbff6062bd1ec34"

--000000000000ddbff6062bd1ec34
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Jan 13, 2025 at 3:27=E2=80=AFPM justina colmena ~biz via selinux <
[email protected]> wrote:

> Mostly I have been running fedora on a home desktop and laptop for a long
> time
> with SELinux enabled, with very minimal workarounds needed. Otherwise I a=
m
> new
> to policies etc. I have just enabled SELinux in permissive mode on a web
> server and followed the instructions here to create a "local_policy.cil"
> policy module file containing a few simple rules, and install it.
>
> https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/
> using_selinux/troubleshooting-problems-related-to-selinux_using-
> <https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html=
/using_selinux/troubleshooting-problems-related-to-selinux_using->
>
> selinux#proc_creating-a-local-selinux-policy-module_troubleshooting-probl=
ems-
> related-to-selinux
>
> Why is PostgreSQL running in unconfined_service_t, and what do I need to
> do to
> allow php-fpm to connect to it?
>
> Isn't there a boolean for that?
>
> [root@blanco ~]# ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR
> -ts
> recent
> ----
> time->Mon Jan 13 13:36:10 2025
> type=3DAVC msg=3Daudit(1736775370.067:3485): avc:  denied  { connectto } =
for
> pid=3D1425 comm=3D"php-fpm" path=3D"/run/postgresql/.s.PGSQL.5432"
> scontext=3Dsystem_u:system_r:httpd_t:s0
> tcontext=3Dsystem_u:system_r:unconfined_service_t:s0
> tclass=3Dunix_stream_socket
> permissive=3D1
> ----
> ...
>
> Do I need a ".cil" rule like this?
>
> (allow  httpd_t unconfined_service_t (unix_stream_socket (connectto)))
>
Hello,

I think that what you need in the first place is to check how the
postgresql service is started. Is the binary properly labeled?

systemctl cat postgresql
ls -lZ /usr/bin/postgres


>
>
>
>
> --
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct:
> https://docs.fedoraproject.org/en-US/project/code-of-conduct/
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedoraproject.org/archives/list/[email protected]=
.org
> Do not reply to spam, report it:
> https://pagure.io/fedora-infrastructure/new_issue
>


--=20

Zdenek Pytela
Security SELinux team

--000000000000ddbff6062bd1ec34
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g=
mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jan 13,=
 2025 at 3:27=E2=80=AFPM justina colmena ~biz via selinux &lt;<a href=3D"ma=
ilto:[email protected]">[email protected]</a>&g=
t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Mostly=
 I have been running fedora on a home desktop and laptop for a long time <b=
r>
with SELinux enabled, with very minimal workarounds needed. Otherwise I am =
new <br>
to policies etc. I have just enabled SELinux in permissive mode on a web <b=
r>
server and followed the instructions here to create a &quot;local_policy.ci=
l&quot; <br>
policy module file containing a few simple rules, and install it.<br>
<br>
<a href=3D"https://docs.redhat.com/en/documentation/red_hat_enterprise_linu=
x/9/html/using_selinux/troubleshooting-problems-related-to-selinux_using-" =
rel=3D"noreferrer" target=3D"_blank">https://docs.redhat.com/en/documentati=
on/red_hat_enterprise_linux/9/html/<br>
using_selinux/troubleshooting-problems-related-to-selinux_using-</a><br>
selinux#proc_creating-a-local-selinux-policy-module_troubleshooting-problem=
s-<br>
related-to-selinux<br>
<br>
Why is PostgreSQL running in unconfined_service_t, and what do I need to do=
 to <br>
allow php-fpm to connect to it?<br>
<br>
Isn&#39;t there a boolean for that?<br>
<br>
[root@blanco ~]# ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts =
<br>
recent<br>
----<br>
time-&gt;Mon Jan 13 13:36:10 2025<br>
type=3DAVC msg=3Daudit(1736775370.067:3485): avc:=C2=A0 denied=C2=A0 { conn=
ectto } for=C2=A0 <br>
pid=3D1425 comm=3D&quot;php-fpm&quot; path=3D&quot;/run/postgresql/.s.PGSQL=
.5432&quot; <br>
scontext=3Dsystem_u:system_r:httpd_t:s0 <br>
tcontext=3Dsystem_u:system_r:unconfined_service_t:s0 tclass=3Dunix_stream_s=
ocket <br>
permissive=3D1<br>
----<br>
...<br>
<br>
Do I need a &quot;.cil&quot; rule like this? <br>
<br>
(allow=C2=A0 httpd_t unconfined_service_t (unix_stream_socket (connectto)))=
<br></blockquote><div>Hello,</div><div><br></div><div>I think that what you=
 need in the first place is to check how the postgresql service is started.=
 Is the binary properly labeled?</div><div><br></div><div><span style=3D"fo=
nt-family:monospace"><span style=3D"color:rgb(0,0,0);background-color:rgb(2=
55,255,255)"> systemctl cat postgresql</span></span></div><div><span style=
=3D"font-family:monospace"><span style=3D"color:rgb(0,0,0);background-color=
:rgb(255,255,255)">ls -lZ /usr/bin/postgres </span><br></span></div><div>=
=C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0=
px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">
<br>
<br>
<br>
<br>
-- <br>
_______________________________________________<br>
selinux mailing list -- <a href=3D"mailto:[email protected]" =
target=3D"_blank">[email protected]</a><br>
To unsubscribe send an email to <a href=3D"mailto:[email protected]=
aproject.org" target=3D"_blank">[email protected]</a><b=
r>
Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro=
ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe=
doraproject.org/en-US/project/code-of-conduct/</a><br>
List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui=
delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik=
i/Mailing_list_guidelines</a><br>
List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel=
[email protected]" rel=3D"noreferrer" target=3D"_blank">https://=
lists.fedoraproject.org/archives/list/[email protected]</a><b=
r>
Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras=
tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/=
fedora-infrastructure/new_issue</a><br>
</blockquote></div><div><br clear=3D"all"></div><br><span class=3D"gmail_si=
gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><d=
iv dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D=
"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br=
>
Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>=
</div></div></div></div></div></div></div></div></div></div></div></div>

--000000000000ddbff6062bd1ec34--


--===============9214125785334939515==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu
dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z
dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl
Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0
Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw
czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB
cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl
bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y
dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo=

--===============9214125785334939515==--