Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: * recent changes in libpcap library cause that various programs suddenly trigger SELinux denials which are related to netlink_rdma_socket class * the ladvd program requires the libpcap library * the ladvd service runs succussfully, but the SELinux denial is logged Version-Release number of selected component (if applicable): ladvd-1.1.2-7.fc33.x86_64 ladvd-selinux-1.1.2-7.fc33.x86_64 libpcap-1.9.1-4.fc33.x86_64 selinux-policy-3.14.6-17.fc33.noarch selinux-policy-targeted-3.14.6-17.fc33.noarch How reproducible: * always Steps to Reproduce: 1. get a Fedora rawhide machine (targeted policy is active) 2. start the ladvd service 3. search for SELinux denials Actual results (enforcing mode): ---- type=PROCTITLE msg=audit(07/09/2020 02:17:53.421:364) : proctitle=ladvd: parent [priv] type=SYSCALL msg=audit(07/09/2020 02:17:53.421:364) : arch=x86_64 syscall=socket success=no exit=EACCES(Permission denied) a0=netlink a1=SOCK_RAW a2=hmp a3=0x0 items=0 ppid=1 pid=1166 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) type=AVC msg=audit(07/09/2020 02:17:53.421:364) : avc: denied { create } for pid=1166 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=0 ---- Expected results: * the ladvd service does not trigger any SELinux denials in default configuration
Following SELinux denials are triggered in permissive mode: ---- type=PROCTITLE msg=audit(07/09/2020 02:33:27.308:373) : proctitle=ladvd: parent [priv] type=SYSCALL msg=audit(07/09/2020 02:33:27.308:373) : arch=x86_64 syscall=socket success=yes exit=11 a0=netlink a1=SOCK_RAW a2=hmp a3=0x11 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) type=AVC msg=audit(07/09/2020 02:33:27.308:373) : avc: denied { module_request } for pid=1231 comm=ladvd kmod="net-pf-16-proto-20" scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=system permissive=1 type=AVC msg=audit(07/09/2020 02:33:27.308:373) : avc: denied { create } for pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 ---- type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:374) : proctitle=ladvd: parent [priv] type=SYSCALL msg=audit(07/09/2020 02:33:27.425:374) : arch=x86_64 syscall=setsockopt success=yes exit=0 a0=0xb a1=SOL_SOCKET a2=SO_SNDBUF a3=0x7ffc6150db18 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) type=AVC msg=audit(07/09/2020 02:33:27.425:374) : avc: denied { setopt } for pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 ---- type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:375) : proctitle=ladvd: parent [priv] type=SOCKADDR msg=audit(07/09/2020 02:33:27.425:375) : saddr={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=1220543695 } type=SYSCALL msg=audit(07/09/2020 02:33:27.425:375) : arch=x86_64 syscall=bind success=yes exit=0 a0=0xb a1=0x561c59cf29c0 a2=0xc a3=0x20 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) type=AVC msg=audit(07/09/2020 02:33:27.425:375) : avc: denied { bind } for pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 ---- type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:376) : proctitle=ladvd: parent [priv] type=SOCKADDR msg=audit(07/09/2020 02:33:27.425:376) : saddr={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=1220543695 } type=SYSCALL msg=audit(07/09/2020 02:33:27.425:376) : arch=x86_64 syscall=getsockname success=yes exit=0 a0=0xb a1=0x7ffc6150db64 a2=0x7ffc6150db60 a3=0x20 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) type=AVC msg=audit(07/09/2020 02:33:27.425:376) : avc: denied { getattr } for pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 ---- If following SELinux rule is added to the ladvd policy module, it should fix the problem: allow ladvd_t self:netlink_rdma_socket { bind create getattr setopt }; I'm not sure about the first AVC, which contains { module_request }. This could be fixed too via appropriate allow/dontaudit rule, or it could be worked around by enabling the domain_kernel_load_modules boolean.
# ldd `which ladvd` linux-vdso.so.1 (0x00007ffc84b6d000) libevent-2.1.so.6 => /lib64/libevent-2.1.so.6 (0x00007fdf6ca25000) -->> libpcap.so.1 => /lib64/libpcap.so.1 (0x00007fdf6c9d5000) libcap-ng.so.0 => /lib64/libcap-ng.so.0 (0x00007fdf6c9cd000) libteam.so.5 => /lib64/libteam.so.5 (0x00007fdf6c9bd000) libc.so.6 => /lib64/libc.so.6 (0x00007fdf6c7f1000) libcrypto.so.1.1 => /lib64/libcrypto.so.1.1 (0x00007fdf6c502000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007fdf6c4de000) libibverbs.so.1 => /lib64/libibverbs.so.1 (0x00007fdf6c4be000) /lib64/ld-linux-x86-64.so.2 (0x00007fdf6caa0000) libnl-cli-3.so.200 => /lib64/libnl-cli-3.so.200 (0x00007fdf6c4b0000) libnl-genl-3.so.200 => /lib64/libnl-genl-3.so.200 (0x00007fdf6c4a6000) libnl-nf-3.so.200 => /lib64/libnl-nf-3.so.200 (0x00007fdf6c48b000) libnl-route-3.so.200 => /lib64/libnl-route-3.so.200 (0x00007fdf6c403000) libnl-3.so.200 => /lib64/libnl-3.so.200 (0x00007fdf6c3dd000) libz.so.1 => /lib64/libz.so.1 (0x00007fdf6c3c3000) libdl.so.2 => /lib64/libdl.so.2 (0x00007fdf6c3bc000) libgcc_s.so.1 => /lib64/libgcc_s.so.1 (0x00007fdf6c3a1000) #
Module AVC is coming from probing VLAN support. I'd rather not open module loading capability for ladvd.
Policy fixes in https://koji.fedoraproject.org/koji/buildinfo?buildID=1584206