Bug 2027691
| Summary: | AVC prevents ping -I from running in UBI 8 container [rhel-8.5.0.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 8 | Reporter: | RHEL Program Management Team <pgm-rhel-tools> |
| Component: | selinux-policy | Assignee: | Zdenek Pytela <zpytela> |
| Status: | CLOSED ERRATA | QA Contact: | Milos Malik <mmalik> |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | 8.5 | CC: | aos-bugs, dwalsh, jnovy, jwboyer, keyoung, lvrabec, miabbott, mmalik, pibanezr, pprahlad, ssekidde, toneata, ykashtan, zpytela |
| Target Milestone: | rc | Keywords: | Triaged, ZStream |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | selinux-policy-3.14.3-80.el8_5.2 | Doc Type: | Bug Fix |
| Doc Text: |
Cause:
The policy does not allow the container_t domain to node_bind to an icmp_socket.
Consequence:
The ping command executed from inside the container is not allowed to set the source address with the "-I" switch.
Fix:
The rule to allow the corenet_unconfined_type attribute to node_bind to icmp_socket was added to the policy.
Result:
"ping -I" works as expected.
|
Story Points: | --- |
| Clone Of: | 2025445 | Environment: | |
| Last Closed: | 2021-12-16 10:05:11 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2025445 | ||
| Bug Blocks: | |||
|
Comment 14
errata-xmlrpc
2021-12-16 10:05:11 UTC
|