Bug 1539416
Summary: | ipsec service with seccomp support and selinux denials | ||
---|---|---|---|
Product: | Red Hat Enterprise Linux 7 | Reporter: | Ondrej Moriš <omoris> |
Component: | selinux-policy | Assignee: | Lukas Vrabec <lvrabec> |
Status: | CLOSED ERRATA | QA Contact: | Ondrej Moriš <omoris> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 7.5 | CC: | jreznik, lvrabec, mgrepl, mmalik, mthacker, omoris, plautrba, pwouters, ssekidde, tis |
Target Milestone: | rc | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | selinux-policy-3.13.1-188.el7 | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2018-04-10 12:49:36 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Ondrej Moriš
2018-01-28 19:30:01 UTC
Paul Wouters noticed one interesting point - there is SELINUX_ERR event which is not really expected, right? Also, Paul suggested that the selinux policy has sysnet_domtrans_ifconfig(ipsec_t) which means ipsec_t should domtrans to ifconfig_t when running ip command and this domain transition in selinux doesn't work when seccomp is enabled for pluto (ipsec daemon). Ondrej Moris and me will test the fix as soon as the new build becomes available. Ondrej, Milos: if you create local policy proposed in description, is the scenario working? Thanks, Lukas. (In reply to Lukas Vrabec from comment #4) > if you create local policy proposed in description, is the scenario working? Yes. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0763 |