Bug 2144500

Summary: AVC error when reloading FRR with provided reload script
Product: Red Hat Enterprise Linux 9 Reporter: Michal Ruprich <mruprich>
Component: frrAssignee: Michal Ruprich <mruprich>
Status: CLOSED ERRATA QA Contact: FrantiĊĦek Hrdina <fhrdina>
Severity: low Docs Contact:
Priority: unspecified    
Version: 9.2CC: fhrdina
Target Milestone: rcKeywords: AutoVerified, Patch, Reproducer, Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: frr-8.3.1-4.el9 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-05-09 07:32:39 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Michal Ruprich 2022-11-21 13:41:57 UTC
Description of problem:
Following AVC is produced when reloading frr config with frr-reload.py:

type=PROCTITLE msg=audit(1669034692.388:332): proctitle=2F7573722F62696E2F707974686F6E33002F7573722F6C6962657865632F6672722F6672722D72656C6F61642E7079002D2D72656C6F6164002F6574632F6672722F6672722E636F6E66
type=SYSCALL msg=audit(1669034692.388:332): arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7f5a10f98650 a2=90800 a3=0 items=0 ppid=5371 pid=5390 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="frr-reload.py" exe="/usr/bin/python3.9" subj=system_u:system_r:frr_t:s0 key=(null)
type=AVC msg=audit(1669034692.388:332): avc:  denied  { read } for  pid=5390 comm="frr-reload.py" name="frr" dev="vda1" ino=37749215 scontext=system_u:system_r:frr_t:s0 tcontext=system_u:object_r:frr_exec_t:s0 tclass=dir permissive=0



Version-Release number of selected component (if applicable):
frr-8.3.1-3.el9

How reproducible:
100%

Steps to Reproduce:
1. systemctl start frr
2. systemctl reload frr <-- no need to change config
3. ausearch -m AVC -ts recent

Actual results:
AVC produced

Expected results:
No AVC.

Comment 10 errata-xmlrpc 2023-05-09 07:32:39 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (Moderate: frr security, bug fix, and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHSA-2023:2202