Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[SELinux] - Kernel message , systemd-udevd - loop0: Failed
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
y351
Apprentice
Apprentice


Joined: 21 May 2017
Posts: 202

PostPosted: Tue Dec 03, 2019 2:34 pm    Post subject: [SELinux] - Kernel message , systemd-udevd - loop0: Failed Reply with quote

Hi,

I get this message from :
Code:

dmesg -H -l err


Code:

systemd-udevd[1460]: loop0: Failed to add device '/dev/loop0' to watch: Permission denied
systemd-udevd[1459]: loop2: Failed to add device '/dev/loop2' to watch: Permission denied
systemd-udevd[1438]: loop3: Failed to add device '/dev/loop3' to watch: Permission denied
systemd-udevd[1442]: loop1: Failed to add device '/dev/loop1' to watch: Permission denied
systemd-udevd[1460]: loop5: Failed to add device '/dev/loop5' to watch: Permission denied
systemd-udevd[1453]: loop4: Failed to add device '/dev/loop4' to watch: Permission denied
systemd-udevd[1459]: loop6: Failed to add device '/dev/loop6' to watch: Permission denied
systemd-udevd[1438]: loop7: Failed to add device '/dev/loop7' to watch: Permission denied


Code:

kernel: [   84.688286] audit: type=1400 audit(1575373431.089:15): avc:  denied  { watch } for  pid=1460 comm="systemd-udevd" path="/dev/loop0" dev="devtmpfs" ino=891 scontext=system_u:system_r:udev_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file permissive=0


I add a policy to get it allow and loaded it :
Code:

[...]
#============= udev_t ==============
# From Boot : devtmpfs  loop3: Failed to add device '/dev/loop3' to watch: Permission denied
allow udev_t fixed_disk_device_t:blk_file { watch };


Code:

Portage 2.3.79 (python 3.6.9-final-0, default/linux/amd64/17.1/hardened/selinux, gcc-9.2.0, glibc-2.29-r2, 5.3.11-gentoo x86_64)
=================================================================
                         System Settings
=================================================================
System uname: Linux-5.3.11-gentoo-x86_64-Intel-R-_Core-TM-_i7-5557U_CPU_@_3.10GHz-with-gentoo-2.6
KiB Mem:    16271356 total,   7715952 free
KiB Swap:    8388604 total,   8388604 free
Timestamp of repository gentoo: Tue, 19 Nov 2019 00:45:01 +0000
Head commit of repository gentoo: 7446f04821448e084c44c24e9f99b46363b62b3e
sh bash 4.4_p23-r1
ld GNU ld (Gentoo 2.32 p2) 2.32.0
ccache version 3.7.4 [enabled]
app-shells/bash:          4.4_p23-r1::gentoo
dev-java/java-config:     2.2.0-r4::gentoo
dev-lang/perl:            5.28.2-r1::gentoo
dev-lang/python:          2.7.16::gentoo, 3.6.9::gentoo
dev-util/ccache:          3.7.4::gentoo
dev-util/cmake:           3.14.6::gentoo
dev-util/pkgconfig:       0.29.2::gentoo
sys-apps/baselayout:      2.6-r1::gentoo
sys-apps/openrc:          0.41.2::gentoo
sys-apps/sandbox:         2.13::gentoo
sys-devel/autoconf:       2.13-r1::gentoo, 2.69-r4::gentoo
sys-devel/automake:       1.11.6-r3::gentoo, 1.16.1-r1::gentoo
sys-devel/binutils:       2.32-r1::gentoo
sys-devel/gcc:            9.2.0-r2::gentoo
sys-devel/gcc-config:     2.1::gentoo
sys-devel/libtool:        2.4.6-r3::gentoo
sys-devel/make:           4.2.1-r4::gentoo
sys-kernel/linux-headers: 4.19::gentoo (virtual/os-headers)
sys-libs/glibc:           2.29-r2::gentoo
Repositories:

gentoo
    location: /usr/portage
    sync-type: rsync
    sync-uri: rsync://rsync.gentoo.org/gentoo-portage
    priority: -1000
    sync-rsync-extra-opts:
    sync-rsync-verify-metamanifest: yes
    sync-rsync-verify-max-age: 24
    sync-rsync-verify-jobs: 1

local
    location: /usr/local/portage
    masters: gentoo
    priority: 10

ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="@FREE"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-march=native -O2 -fforce-addr -pipe"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/share/gnupg/qualified.txt"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/dconf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-march=native -O2 -fforce-addr -pipe"
DISTDIR="/usr/portage/distfiles"
EMERGE_DEFAULT_OPTS="--jobs=4 --load-average=4.0 --keep-going=y --with-bdeps=y --complete-graph"
ENV_UNSET="DBUS_SESSION_BUS_ADDRESS DISPLAY GOBIN PERL5LIB PERL5OPT PERLPREFIX PERL_CORE PERL_MB_OPT PERL_MM_OPT XAUTHORITY XDG_CACHE_HOME XDG_CONFIG_HOME XDG_DATA_HOME XDG_RUNTIME_DIR"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-docompress binpkg-dostrip binpkg-logs buildpkg ccache config-protect-if-modified distlocks ebuild-locks fixlafiles ipc-sandbox merge-sync multilib-strict network-sandbox news parallel-fetch parallel-install preserve-libs protect-owned sandbox selinux sesandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://m.toto.org/gentoo/"
LANG="fr_FR.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j5"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages --exclude=/.git"
PORTAGE_TMPDIR="/var/tmp"
USE="X acl amd64 branding bzip2 chroot consolekit crypt cryptsetup cxx ffmpeg gnutls hardened iconv icu ipv6 jpeg libtirpc logrotate lzma mmx modplug multilib ncurses nls nptl opengl openmp pam pax_kernel pcre perl pic pie png python readline seccomp secure_delete selinux snmp split-usr sse sse2 ssl ssp symlink tcpd unicode wavpack webrsync-gpg xattr xml xtpax zlib" ABI_X86="64" ADA_TARGET="gnat_2018" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="authn_core authz_core socache_shmcb unixd actions alias auth_basic authn_alias authn_anon authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache cgi cgid dav dav_fs dav_lock deflate dir disk_cache env expires ext_filter file_cache filter headers include info log_config logio mem_cache mime mime_magic negotiation rewrite setenvif speling status unique_id userdir usertrack vhost_alias" CALLIGRA_FEATURES="karbon sheets words" COLLECTD_PLUGINS="load memory syslog" CPU_FLAGS_X86="aes avx avx2 f16c fma3 mmx mmxext pclmul popcnt sse sse2 sse3 sse4_1 sse4_2 ssse3" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock greis isync itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf skytraq superstar2 timing tsip tripmate tnt ublox ubx" GRUB_PLATFORMS="efi-64" INPUT_DEVICES="evdev keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" NETBEANS_MODULES="apisupport cnd groovy gsf harness ide identity j2ee java mobility nb php profiler soa visualweb webcommon websvccommon xml" OFFICE_IMPLEMENTATION="libreoffice" PHP_TARGETS="php7-2" POSTGRES_TARGETS="postgres10 postgres11" PYTHON_SINGLE_TARGET="python3_6" PYTHON_TARGETS="python2_7 python3_6" QEMU_SOFTMMU_TARGETS="arm x86_64 sparc" QEMU_USER_TARGETS="x86_64" RUBY_TARGETS="ruby24 ruby25" USERLAND="GNU" VIDEO_CARDS="intel i915" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CC, CPPFLAGS, CTARGET, CXX, INSTALL_MASK, LC_ALL, LINGUAS, PORTAGE_BINHOST, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS

=================================================================
                        Package Settings
=================================================================

sys-fs/udev-243-r2::gentoo was built with the following:
USE="acl kmod (selinux) (split-usr) -static-libs" ABI_X86="(64) -32 (-x32)"


There is no systemd installed.

Any idea would appreciated.

Thanks in advance.

[Moderator edit: changed [quote] tags to [code] tags to preserve output layout. -Hu]
Back to top
View user's profile Send private message
papas
Tux's lil' helper
Tux's lil' helper


Joined: 01 Dec 2014
Posts: 141
Location: Athens

PostPosted: Sat Dec 07, 2019 1:36 pm    Post subject: Reply with quote

use eudev instead of udev
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23193

PostPosted: Sat Dec 07, 2019 4:52 pm    Post subject: Reply with quote

papas wrote:
use eudev instead of udev
While I prefer eudev, I must ask, what in the OP's post led you to state that eudev will solve the problem? This does not appear to be something where eudev will behave differently.
Back to top
View user's profile Send private message
papas
Tux's lil' helper
Tux's lil' helper


Joined: 01 Dec 2014
Posts: 141
Location: Athens

PostPosted: Sat Dec 07, 2019 5:14 pm    Post subject: Reply with quote

The truth is that i don't know what the problem is, but I am under Selinux, with eudev never had similar problems, i am sorry for the confusion :oops:
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23193

PostPosted: Sun Dec 08, 2019 5:36 pm    Post subject: Reply with quote

This looks suspiciously similar to the newer thread [SELinux] kernel 5.4.x: No support for "watch". That thread is not solved yet, but the opening post has some promising analysis in it.
Back to top
View user's profile Send private message
alamahant
Advocate
Advocate


Joined: 23 Mar 2019
Posts: 3958

PostPosted: Sun Dec 08, 2019 7:08 pm    Post subject: Reply with quote

If you try to relabel the system?
Was it working before?
Try this:
Quote:
touch /.autorelabel

and reboot.
This will relabel the whole system selinux contexts.....
Back to top
View user's profile Send private message
deagol
n00b
n00b


Joined: 12 Jul 2014
Posts: 62

PostPosted: Mon Dec 09, 2019 9:04 pm    Post subject: Reply with quote

y351 wrote:
Code:
kernel: [   84.688286] audit: type=1400 audit(1575373431.089:15): avc:  denied  { watch } for  pid=1460 comm="systemd-udevd" path="/dev/loop0" dev="devtmpfs" ino=891 scontext=system_u:system_r:udev_t tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file permissive=0

This indeed looks similar to the issue I reported in [SELinux] kernel 5.4.x: No support for "watch"

But something is strange here: According to the output of "emerge --info" you provided you are running kernel 5.3.11-gentoo. But this kernel does not have the "watch" permission at all. (At least my newer sys-kernel/gentoo-sources-5.3.13 does not have it...) So I don't see any way how you could get the above error with a stable kernel < 5.4.0 or applying custom patches, backporting newer features. I assume you reverted back to 5.3.11 at the time you generated that output, but did not see the problems with that kernel, correct?

Now assuming you have ac5656d8a4cd ("fanotify, inotify, dnotify, security: add security hook for fs notifications") in your kernel try to revert it. It solved my problems and it really looks like it "solve" yours also. And I'm starting to suspect that is indeed the correct solution for now.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum