Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: After upgrading F22 to F23 hostapd is no more working if SELinux is enforced. An attempt to start the hostapd.service fails. These are the syslog errors around the AVC: Nov 05 20:45:05 blackmix systemd[1]: Starting Hostapd IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator... -- Subject: Unit hostapd.service has begun start-up -- Defined-By: systemd -- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel -- -- Unit hostapd.service has begun starting up. Nov 05 20:45:05 blackmix hostapd[3051]: Configuration file: /etc/hostapd/hostapd.conf Nov 05 20:45:05 blackmix audit[3051]: AVC avc: denied { create } for pid=3051 comm="hostapd" scontext=system_u:system_r:hostapd_t:s0 tcontext=system_u:system_r:hostapd_t:s0 tcla Nov 05 20:45:05 blackmix hostapd[3051]: nl80211: Failed to connect to generic netlink (nl) Nov 05 20:45:05 blackmix hostapd[3051]: Failed to initialize driver 'nl80211' Nov 05 20:45:05 blackmix hostapd[3051]: wlp4s0: interface state UNINITIALIZED->DISABLED Nov 05 20:45:05 blackmix hostapd[3051]: wlp4s0: AP-DISABLED Nov 05 20:45:05 blackmix hostapd[3051]: hostapd_free_hapd_data: Interface wlp4s0 wasn't started Nov 05 20:45:05 blackmix systemd[1]: hostapd.service: Control process exited, code=exited status=1 Nov 05 20:45:05 blackmix systemd[1]: Failed to start Hostapd IEEE 802.11 AP, IEEE 802.1X/WPA/WPA2/EAP/RADIUS Authenticator. -- Subject: Unit hostapd.service has failed -- Defined-By: systemd -- Support: http://lists.freedesktop.org/mailman/listinfo/systemd-devel -- -- Unit hostapd.service has failed. -- -- The result is failed. This used to work on F22. It is also working in F23 if SELinux is set to permissive. SELinux is preventing hostapd from 'create' accesses on the netlink_generic_socket Unknown. ***** Plugin catchall (100. confidence) suggests ************************** If sie denken, dass es hostapd standardmässig erlaubt sein sollte, create Zugriff auf Unknown netlink_generic_socket zu erhalten. Then sie sollten dies als Fehler melden. Um diesen Zugriff zu erlauben, können Sie ein lokales Richtlinien-Modul erstellen. Do zugriff jetzt erlauben, indem Sie die nachfolgenden Befehle ausführen: # grep hostapd /var/log/audit/audit.log | audit2allow -M mypol # semodule -i mypol.pp Additional Information: Source Context system_u:system_r:hostapd_t:s0 Target Context system_u:system_r:hostapd_t:s0 Target Objects Unknown [ netlink_generic_socket ] Source hostapd Source Path hostapd Port <Unknown> Host (removed) Source RPM Packages Target RPM Packages Policy RPM selinux-policy-3.13.1-152.fc23.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name (removed) Platform Linux (removed) 4.2.5-300.fc23.x86_64 #1 SMP Tue Oct 27 04:29:56 UTC 2015 x86_64 x86_64 Alert Count 14 First Seen 2015-10-28 23:18:08 CET Last Seen 2015-11-05 20:45:05 CET Local ID 82450dd7-76a4-4287-a662-d36277618759 Raw Audit Messages type=AVC msg=audit(1446752705.265:659): avc: denied { create } for pid=3051 comm="hostapd" scontext=system_u:system_r:hostapd_t:s0 tcontext=system_u:system_r:hostapd_t:s0 tclass=netlink_generic_socket permissive=0 Hash: hostapd,hostapd_t,hostapd_t,netlink_generic_socket,create Version-Release number of selected component: selinux-policy-3.13.1-152.fc23.noarch Additional info: reporter: libreport-2.6.3 hashmarkername: setroubleshoot kernel: 4.2.5-300.fc23.x86_64 type: libreport
*** This bug has been marked as a duplicate of bug 1266068 ***