adamant-kite-43734
09/22/2022, 7:09 PMswift-zebra-42479
09/23/2022, 5:58 AMabundant-yak-72647
09/25/2022, 4:30 AMadamant-kite-43734
09/26/2022, 1:04 PMadamant-kite-43734
09/26/2022, 1:16 PMadamant-kite-43734
09/26/2022, 6:52 PMshy-zebra-53074
09/27/2022, 3:40 PM1.22.15
even though I’m being very explicit in all of my config optionsadamant-kite-43734
09/27/2022, 3:40 PMshy-zebra-53074
09/27/2022, 3:41 PMlatest
stable
and testing
shy-zebra-53074
09/27/2022, 3:43 PM1.22.13
worked but not 1.22.14
/ 1.22.15
shy-zebra-53074
09/27/2022, 3:43 PMadamant-kite-43734
09/28/2022, 6:23 PMadamant-kite-43734
09/28/2022, 8:52 PMadamant-kite-43734
09/29/2022, 11:07 AMshy-zebra-53074
09/29/2022, 3:31 PMfapolicyd
continuing to block runc
even though it’s been allowed as a rule AND added to the trust database??shy-zebra-53074
09/29/2022, 3:33 PM[root@ip-192-168-96-10 ~]# cat /etc/fapolicyd/rules.d/01-app.rules
# uids
%uuids=0,1000
# Run RKE2
allow perm=any all : dir=/opt/cni/
allow perm=any all : dir=/run/k3s/
allow perm=any all : dir=/var/lib/kubelet/
allow perm=any all : dir=/var/lib/rancher/
allow perm=any all : dir=/var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/
allow perm=any all : dir=/var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/runc
shy-zebra-53074
09/29/2022, 3:34 PM[root@ip-192-168-96-10 ~]# cat /etc/fapolicyd/trust.d/app
# AUTOGENERATED FILE VERSION 2
# This file contains a list of trusted files
#
# FULL PATH SIZE SHA256
# /home/user/my-ls 157984 61a9960bf7d255a85811f4afcac51067b8f2e4c75e21cf4f2af95319d4ed1b87
/usr/bin/unzip 206704 299d6bae8ec58c76e087f8516cb6be438db2481bbab9b2b61a6c6a5c206a27f3
/var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/runc 11068888 b3276789a9b735b758e6292ce469192c9ef77514bf7fa3b3fef77d631a4e4ee3
shy-zebra-53074
09/29/2022, 3:34 PM[root@ip-192-168-96-10 ~]# sha256sum /var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/runc
b3276789a9b735b758e6292ce469192c9ef77514bf7fa3b3fef77d631a4e4ee3 /var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/runc
shy-zebra-53074
09/29/2022, 3:35 PM[root@ip-192-168-96-10 ~]# ausearch -m fanotify --raw | aureport --file --summary
File Summary Report
===========================
total file
===========================
609 /var/lib/rancher/rke2/data/v1.22.6-rke2r1-e6c1502b55cd/bin/runc
shy-zebra-53074
09/29/2022, 4:21 PMadamant-kite-43734
09/30/2022, 1:10 PMadamant-kite-43734
10/03/2022, 11:20 AMshy-zebra-53074
10/03/2022, 6:00 PMfapolicyd
here’s a thread I had that resolved my issue: https://github.com/linux-application-whitelisting/fapolicyd/issues/205ancient-air-32350
10/03/2022, 8:19 PMadamant-kite-43734
10/03/2022, 8:57 PMadamant-kite-43734
10/05/2022, 1:52 PMadamant-kite-43734
10/05/2022, 6:06 PMgreat-flag-38820
10/06/2022, 4:59 AMadamant-kite-43734
10/06/2022, 6:12 PMadamant-kite-43734
10/06/2022, 6:53 PM