Re: Fixing denials
Zdenek Pytela via selinux <[email protected]> Thu, 16 Jan 2025 13:27:51 +0100
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <CAO4UijDs6PCff44kGo_4g7abe2bRXUhNdZ6hUDx2Q=wBMgDu+w@mail.gmail.com> |
--===============9214125785334939515== Content-Type: multipart/alternative; boundary="000000000000ddbff6062bd1ec34" --000000000000ddbff6062bd1ec34 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Mon, Jan 13, 2025 at 3:27=E2=80=AFPM justina colmena ~biz via selinux < [email protected]> wrote: > Mostly I have been running fedora on a home desktop and laptop for a long > time > with SELinux enabled, with very minimal workarounds needed. Otherwise I a= m > new > to policies etc. I have just enabled SELinux in permissive mode on a web > server and followed the instructions here to create a "local_policy.cil" > policy module file containing a few simple rules, and install it. > > https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/ > using_selinux/troubleshooting-problems-related-to-selinux_using- > <https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html= /using_selinux/troubleshooting-problems-related-to-selinux_using-> > > selinux#proc_creating-a-local-selinux-policy-module_troubleshooting-probl= ems- > related-to-selinux > > Why is PostgreSQL running in unconfined_service_t, and what do I need to > do to > allow php-fpm to connect to it? > > Isn't there a boolean for that? > > [root@blanco ~]# ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR > -ts > recent > ---- > time->Mon Jan 13 13:36:10 2025 > type=3DAVC msg=3Daudit(1736775370.067:3485): avc: denied { connectto } = for > pid=3D1425 comm=3D"php-fpm" path=3D"/run/postgresql/.s.PGSQL.5432" > scontext=3Dsystem_u:system_r:httpd_t:s0 > tcontext=3Dsystem_u:system_r:unconfined_service_t:s0 > tclass=3Dunix_stream_socket > permissive=3D1 > ---- > ... > > Do I need a ".cil" rule like this? > > (allow httpd_t unconfined_service_t (unix_stream_socket (connectto))) > Hello, I think that what you need in the first place is to check how the postgresql service is started. Is the binary properly labeled? systemctl cat postgresql ls -lZ /usr/bin/postgres > > > > > -- > _______________________________________________ > selinux mailing list -- [email protected] > To unsubscribe send an email to [email protected] > Fedora Code of Conduct: > https://docs.fedoraproject.org/en-US/project/code-of-conduct/ > List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines > List Archives: > https://lists.fedoraproject.org/archives/list/[email protected]= .org > Do not reply to spam, report it: > https://pagure.io/fedora-infrastructure/new_issue > --=20 Zdenek Pytela Security SELinux team --000000000000ddbff6062bd1ec34 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Jan 13,= 2025 at 3:27=E2=80=AFPM justina colmena ~biz via selinux <<a href=3D"ma= ilto:[email protected]">[email protected]</a>&g= t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p= x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Mostly= I have been running fedora on a home desktop and laptop for a long time <b= r> with SELinux enabled, with very minimal workarounds needed. Otherwise I am = new <br> to policies etc. I have just enabled SELinux in permissive mode on a web <b= r> server and followed the instructions here to create a "local_policy.ci= l" <br> policy module file containing a few simple rules, and install it.<br> <br> <a href=3D"https://docs.redhat.com/en/documentation/red_hat_enterprise_linu= x/9/html/using_selinux/troubleshooting-problems-related-to-selinux_using-" = rel=3D"noreferrer" target=3D"_blank">https://docs.redhat.com/en/documentati= on/red_hat_enterprise_linux/9/html/<br> using_selinux/troubleshooting-problems-related-to-selinux_using-</a><br> selinux#proc_creating-a-local-selinux-policy-module_troubleshooting-problem= s-<br> related-to-selinux<br> <br> Why is PostgreSQL running in unconfined_service_t, and what do I need to do= to <br> allow php-fpm to connect to it?<br> <br> Isn't there a boolean for that?<br> <br> [root@blanco ~]# ausearch -m AVC,USER_AVC,SELINUX_ERR,USER_SELINUX_ERR -ts = <br> recent<br> ----<br> time->Mon Jan 13 13:36:10 2025<br> type=3DAVC msg=3Daudit(1736775370.067:3485): avc:=C2=A0 denied=C2=A0 { conn= ectto } for=C2=A0 <br> pid=3D1425 comm=3D"php-fpm" path=3D"/run/postgresql/.s.PGSQL= .5432" <br> scontext=3Dsystem_u:system_r:httpd_t:s0 <br> tcontext=3Dsystem_u:system_r:unconfined_service_t:s0 tclass=3Dunix_stream_s= ocket <br> permissive=3D1<br> ----<br> ...<br> <br> Do I need a ".cil" rule like this? <br> <br> (allow=C2=A0 httpd_t unconfined_service_t (unix_stream_socket (connectto)))= <br></blockquote><div>Hello,</div><div><br></div><div>I think that what you= need in the first place is to check how the postgresql service is started.= Is the binary properly labeled?</div><div><br></div><div><span style=3D"fo= nt-family:monospace"><span style=3D"color:rgb(0,0,0);background-color:rgb(2= 55,255,255)"> systemctl cat postgresql</span></span></div><div><span style= =3D"font-family:monospace"><span style=3D"color:rgb(0,0,0);background-color= :rgb(255,255,255)">ls -lZ /usr/bin/postgres </span><br></span></div><div>= =C2=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0= px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <br> <br> <br> <br> -- <br> _______________________________________________<br> selinux mailing list -- <a href=3D"mailto:[email protected]" = target=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]= aproject.org" target=3D"_blank">[email protected]</a><b= r> Fedora Code of Conduct: <a href=3D"https://docs.fedoraproject.org/en-US/pro= ject/code-of-conduct/" rel=3D"noreferrer" target=3D"_blank">https://docs.fe= doraproject.org/en-US/project/code-of-conduct/</a><br> List Guidelines: <a href=3D"https://fedoraproject.org/wiki/Mailing_list_gui= delines" rel=3D"noreferrer" target=3D"_blank">https://fedoraproject.org/wik= i/Mailing_list_guidelines</a><br> List Archives: <a href=3D"https://lists.fedoraproject.org/archives/list/sel= [email protected]" rel=3D"noreferrer" target=3D"_blank">https://= lists.fedoraproject.org/archives/list/[email protected]</a><b= r> Do not reply to spam, report it: <a href=3D"https://pagure.io/fedora-infras= tructure/new_issue" rel=3D"noreferrer" target=3D"_blank">https://pagure.io/= fedora-infrastructure/new_issue</a><br> </blockquote></div><div><br clear=3D"all"></div><br><span class=3D"gmail_si= gnature_prefix">-- </span><br><div dir=3D"ltr" class=3D"gmail_signature"><d= iv dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D= "ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><div><div dir=3D"ltr"><br= > Zdenek Pytela</div><div dir=3D"ltr">Security SELinux team</div></div></div>= </div></div></div></div></div></div></div></div></div></div></div></div> --000000000000ddbff6062bd1ec34-- --===============9214125785334939515== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCl9fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fCnNlbGlu dXggbWFpbGluZyBsaXN0IC0tIHNlbGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKVG8gdW5z dWJzY3JpYmUgc2VuZCBhbiBlbWFpbCB0byBzZWxpbnV4LWxlYXZlQGxpc3RzLmZlZG9yYXByb2pl Y3Qub3JnCkZlZG9yYSBDb2RlIG9mIENvbmR1Y3Q6IGh0dHBzOi8vZG9jcy5mZWRvcmFwcm9qZWN0 Lm9yZy9lbi1VUy9wcm9qZWN0L2NvZGUtb2YtY29uZHVjdC8KTGlzdCBHdWlkZWxpbmVzOiBodHRw czovL2ZlZG9yYXByb2plY3Qub3JnL3dpa2kvTWFpbGluZ19saXN0X2d1aWRlbGluZXMKTGlzdCBB cmNoaXZlczogaHR0cHM6Ly9saXN0cy5mZWRvcmFwcm9qZWN0Lm9yZy9hcmNoaXZlcy9saXN0L3Nl bGludXhAbGlzdHMuZmVkb3JhcHJvamVjdC5vcmcKRG8gbm90IHJlcGx5IHRvIHNwYW0sIHJlcG9y dCBpdDogaHR0cHM6Ly9wYWd1cmUuaW8vZmVkb3JhLWluZnJhc3RydWN0dXJlL25ld19pc3N1ZQo= --===============9214125785334939515==--