Bug #71532 [NEW]: Child terminates when SELinux denies access to library

From: Date: Fri, 05 Feb 2016 10:17:46 +0000
Subject: Bug #71532 [NEW]: Child terminates when SELinux denies access to library
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199064@lists.php.net to get a copy of this message
From: david at davidsteinsland dot net Operating system: CentOS 7 64-bit PHP version: 5.6.18 Package: FPM related Bug Type: Bug Bug description:Child terminates when SELinux denies access to library Description: ------------ When I was setting up a PHP extension I compiled it by providing an absolute path to the library it needed. After installing, I copied the library to /usr/lib64. The directory in which I compiled the extension, was /root/. All seemed fine, running php -m showed the extension loaded. However, php-fpm filled the log with: [05-Feb-2016 10:57:05] NOTICE: Terminating ... [05-Feb-2016 10:57:05] ALERT: oops, unknown child (16001) exited with code 0. Please open a bug report (https://bugs.php.net). [05-Feb-2016 10:57:05] NOTICE: exiting, bye-bye! [05-Feb-2016 10:57:05] NOTICE: fpm is running, pid 16137 [05-Feb-2016 10:57:05] NOTICE: ready to handle connections [05-Feb-2016 10:57:05] NOTICE: systemd monitor interval set to 10000ms When viewing the audit log, I noticed that PHP was trying to load the library (that the extension needed), from /root/: type=AVC msg=audit(1454666387.325:13883): avc: denied { read } for pid=16285 comm="php-fpm" name="libxl.so" dev="dm-0" ino=17751008 scontext=system_u:system_r:httpd_t:s0 tcontext=unconfined_u:object_r:admin_home_t:s0 tclass=file Note the "admin_home_t" security context of the target. I recompiled the extension, but this time I provided the absolute path to the library as /usr/lib64/libxl.so Not a bug per sè, but it seems that php-fpm doesn't handles denial of access that SELinux causes. The log output doesn't tell anything about SELinux, only that the child terminated. Expected result: ---------------- Library should be loaded from /usr/lib64/ in the first place. Log should be more clear. Actual result: -------------- Library tried loaded from /root/. Log not clear about this. -- Edit bug report at https://bugs.php.net/bug.php?id=71532&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=71532&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=71532&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=71532&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=71532&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=71532&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=71532&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=71532&r=needscript Try newer version: https://bugs.php.net/fix.php?id=71532&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=71532&r=support Expected behavior: https://bugs.php.net/fix.php?id=71532&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=71532&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=71532&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=71532&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=71532&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=71532&r=dst IIS Stability: https://bugs.php.net/fix.php?id=71532&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=71532&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=71532&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=71532&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=71532&r=mysqlcfg

« previous php.bugs (#199064) next »