Bug #71532 [NEW]: Child terminates when SELinux denies access to library
| From: | david at davidsteinsland dot net | Date: | Fri, 05 Feb 2016 10:17:46 +0000 |
| Subject: | Bug #71532 [NEW]: Child terminates when SELinux denies access to library | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-199064@lists.php.net to get a copy of this message | ||
From: david at davidsteinsland dot net
Operating system: CentOS 7 64-bit
PHP version: 5.6.18
Package: FPM related
Bug Type: Bug
Bug description:Child terminates when SELinux denies access to library
Description:
------------
When I was setting up a PHP extension I compiled it by providing an
absolute path to the library it needed. After installing, I copied the
library to /usr/lib64.
The directory in which I compiled the extension, was /root/.
All seemed fine, running php -m showed the extension loaded.
However, php-fpm filled the log with:
[05-Feb-2016 10:57:05] NOTICE: Terminating ...
[05-Feb-2016 10:57:05] ALERT: oops, unknown child (16001) exited with
code 0. Please open a bug report (https://bugs.php.net).
[05-Feb-2016 10:57:05] NOTICE: exiting, bye-bye!
[05-Feb-2016 10:57:05] NOTICE: fpm is running, pid 16137
[05-Feb-2016 10:57:05] NOTICE: ready to handle connections
[05-Feb-2016 10:57:05] NOTICE: systemd monitor interval set to 10000ms
When viewing the audit log, I noticed that PHP was trying to load the
library (that the extension needed), from /root/:
type=AVC msg=audit(1454666387.325:13883): avc: denied { read } for
pid=16285 comm="php-fpm" name="libxl.so" dev="dm-0" ino=17751008
scontext=system_u:system_r:httpd_t:s0
tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file
Note the "admin_home_t" security context of the target.
I recompiled the extension, but this time I provided the absolute path
to the library as /usr/lib64/libxl.so
Not a bug per sè, but it seems that php-fpm doesn't handles denial of
access that SELinux causes. The log output doesn't tell anything about
SELinux, only that the child terminated.
Expected result:
----------------
Library should be loaded from /usr/lib64/ in the first place.
Log should be more clear.
Actual result:
--------------
Library tried loaded from /root/.
Log not clear about this.
--
Edit bug report at https://bugs.php.net/bug.php?id=71532&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71532&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71532&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71532&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=71532&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=71532&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=71532&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=71532&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=71532&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=71532&r=support
Expected behavior: https://bugs.php.net/fix.php?id=71532&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=71532&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=71532&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=71532&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71532&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=71532&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=71532&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=71532&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=71532&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=71532&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=71532&r=mysqlcfg