Skip to content

Conversation

@zpytela
Copy link
Contributor

@zpytela zpytela commented Nov 21, 2025

The commit addresses the following AVC denials:
type=AVC msg=audit(1761761320.303:568): avc: denied { search } for pid=1490 comm="systemd-machine" name="19272" dev="proc" ino=31558 scontext=system_u:system_r:systemd_machined_t:s0 tcontext=system_u:system_r:svirt_t:s0:c825,c980 tclass=dir permissive=0 type=AVC msg=audit(1761787546.949:757): avc: denied { open } for pid=1075 comm="systemd-machine" path="/proc/32908/stat" dev="proc" ino=169265 scontext=system_u:system_r:systemd_machined_t:s0 tcontext=system_u:system_r:svirt_t:s0:c274,c314 tclass=file permissive=0

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2407206

As a result of systemd commit 119d332d9c2c [1] ("machine: do not allow
unprivileged users to register other users' processes as machines"),
additional checks for unprivileged users are now performed in machined.
[1] systemd/systemd@119d332

The commit addresses the following AVC denials:
type=AVC msg=audit(1761761320.303:568): avc:  denied  { search } for  pid=1490 comm="systemd-machine" name="19272" dev="proc" ino=31558 scontext=system_u:system_r:systemd_machined_t:s0 tcontext=system_u:system_r:svirt_t:s0:c825,c980 tclass=dir permissive=0
type=AVC msg=audit(1761787546.949:757): avc:  denied  { open } for  pid=1075 comm="systemd-machine" path="/proc/32908/stat" dev="proc" ino=169265 scontext=system_u:system_r:systemd_machined_t:s0 tcontext=system_u:system_r:svirt_t:s0:c274,c314 tclass=file permissive=0

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2407206
@zpytela zpytela merged commit 6516360 into fedora-selinux:rawhide Nov 24, 2025
4 checks passed
@zpytela zpytela deleted the machined-libvirt branch November 24, 2025 08:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant