Bug 1855163 - the ladvd service triggers SELinux denials because of libpcap changes
Summary: the ladvd service triggers SELinux denials because of libpcap changes
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: ladvd
Version: rawhide
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Tomasz Torcz
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-07-09 06:33 UTC by Milos Malik
Modified: 2020-08-05 07:01 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2020-08-05 07:01:03 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Milos Malik 2020-07-09 06:33:03 UTC
Description of problem:
 * recent changes in libpcap library cause that various programs suddenly trigger SELinux denials which are related to netlink_rdma_socket class
 * the ladvd program requires the libpcap library
 * the ladvd service runs succussfully, but the SELinux denial is logged

Version-Release number of selected component (if applicable):
ladvd-1.1.2-7.fc33.x86_64
ladvd-selinux-1.1.2-7.fc33.x86_64
libpcap-1.9.1-4.fc33.x86_64
selinux-policy-3.14.6-17.fc33.noarch
selinux-policy-targeted-3.14.6-17.fc33.noarch

How reproducible:
 * always

Steps to Reproduce:
1. get a Fedora rawhide machine (targeted policy is active)
2. start the ladvd service
3. search for SELinux denials

Actual results (enforcing mode):
----
type=PROCTITLE msg=audit(07/09/2020 02:17:53.421:364) : proctitle=ladvd: parent [priv] 
type=SYSCALL msg=audit(07/09/2020 02:17:53.421:364) : arch=x86_64 syscall=socket success=no exit=EACCES(Permission denied) a0=netlink a1=SOCK_RAW a2=hmp a3=0x0 items=0 ppid=1 pid=1166 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) 
type=AVC msg=audit(07/09/2020 02:17:53.421:364) : avc:  denied  { create } for  pid=1166 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=0 
----

Expected results:
 * the ladvd service does not trigger any SELinux denials in default configuration

Comment 1 Milos Malik 2020-07-09 06:39:52 UTC
Following SELinux denials are triggered in permissive mode:
----
type=PROCTITLE msg=audit(07/09/2020 02:33:27.308:373) : proctitle=ladvd: parent [priv] 
type=SYSCALL msg=audit(07/09/2020 02:33:27.308:373) : arch=x86_64 syscall=socket success=yes exit=11 a0=netlink a1=SOCK_RAW a2=hmp a3=0x11 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) 
type=AVC msg=audit(07/09/2020 02:33:27.308:373) : avc:  denied  { module_request } for  pid=1231 comm=ladvd kmod="net-pf-16-proto-20" scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:kernel_t:s0 tclass=system permissive=1 
type=AVC msg=audit(07/09/2020 02:33:27.308:373) : avc:  denied  { create } for  pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 
----
type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:374) : proctitle=ladvd: parent [priv] 
type=SYSCALL msg=audit(07/09/2020 02:33:27.425:374) : arch=x86_64 syscall=setsockopt success=yes exit=0 a0=0xb a1=SOL_SOCKET a2=SO_SNDBUF a3=0x7ffc6150db18 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) 
type=AVC msg=audit(07/09/2020 02:33:27.425:374) : avc:  denied  { setopt } for  pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 
----
type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:375) : proctitle=ladvd: parent [priv] 
type=SOCKADDR msg=audit(07/09/2020 02:33:27.425:375) : saddr={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=1220543695 } 
type=SYSCALL msg=audit(07/09/2020 02:33:27.425:375) : arch=x86_64 syscall=bind success=yes exit=0 a0=0xb a1=0x561c59cf29c0 a2=0xc a3=0x20 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) 
type=AVC msg=audit(07/09/2020 02:33:27.425:375) : avc:  denied  { bind } for  pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 
----
type=PROCTITLE msg=audit(07/09/2020 02:33:27.425:376) : proctitle=ladvd: parent [priv] 
type=SOCKADDR msg=audit(07/09/2020 02:33:27.425:376) : saddr={ saddr_fam=netlink nlnk-fam=16 nlnk-pid=1220543695 } 
type=SYSCALL msg=audit(07/09/2020 02:33:27.425:376) : arch=x86_64 syscall=getsockname success=yes exit=0 a0=0xb a1=0x7ffc6150db64 a2=0x7ffc6150db60 a3=0x20 items=0 ppid=1 pid=1231 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=ladvd exe=/usr/sbin/ladvd subj=system_u:system_r:ladvd_t:s0 key=(null) 
type=AVC msg=audit(07/09/2020 02:33:27.425:376) : avc:  denied  { getattr } for  pid=1231 comm=ladvd scontext=system_u:system_r:ladvd_t:s0 tcontext=system_u:system_r:ladvd_t:s0 tclass=netlink_rdma_socket permissive=1 
----

If following SELinux rule is added to the ladvd policy module, it should fix the problem:

allow ladvd_t self:netlink_rdma_socket { bind create getattr setopt };

I'm not sure about the first AVC, which contains { module_request }. This could be fixed too via appropriate allow/dontaudit rule, or it could be worked around by enabling the domain_kernel_load_modules boolean.

Comment 2 Milos Malik 2020-07-09 06:41:25 UTC
# ldd `which ladvd`
	linux-vdso.so.1 (0x00007ffc84b6d000)
	libevent-2.1.so.6 => /lib64/libevent-2.1.so.6 (0x00007fdf6ca25000)
-->>    libpcap.so.1 => /lib64/libpcap.so.1 (0x00007fdf6c9d5000)
	libcap-ng.so.0 => /lib64/libcap-ng.so.0 (0x00007fdf6c9cd000)
	libteam.so.5 => /lib64/libteam.so.5 (0x00007fdf6c9bd000)
	libc.so.6 => /lib64/libc.so.6 (0x00007fdf6c7f1000)
	libcrypto.so.1.1 => /lib64/libcrypto.so.1.1 (0x00007fdf6c502000)
	libpthread.so.0 => /lib64/libpthread.so.0 (0x00007fdf6c4de000)
	libibverbs.so.1 => /lib64/libibverbs.so.1 (0x00007fdf6c4be000)
	/lib64/ld-linux-x86-64.so.2 (0x00007fdf6caa0000)
	libnl-cli-3.so.200 => /lib64/libnl-cli-3.so.200 (0x00007fdf6c4b0000)
	libnl-genl-3.so.200 => /lib64/libnl-genl-3.so.200 (0x00007fdf6c4a6000)
	libnl-nf-3.so.200 => /lib64/libnl-nf-3.so.200 (0x00007fdf6c48b000)
	libnl-route-3.so.200 => /lib64/libnl-route-3.so.200 (0x00007fdf6c403000)
	libnl-3.so.200 => /lib64/libnl-3.so.200 (0x00007fdf6c3dd000)
	libz.so.1 => /lib64/libz.so.1 (0x00007fdf6c3c3000)
	libdl.so.2 => /lib64/libdl.so.2 (0x00007fdf6c3bc000)
	libgcc_s.so.1 => /lib64/libgcc_s.so.1 (0x00007fdf6c3a1000)
#

Comment 3 Tomasz Torcz 2020-08-05 06:32:24 UTC
Module AVC is coming from probing VLAN support. I'd rather not open module loading capability for ladvd.

Comment 4 Tomasz Torcz 2020-08-05 07:01:03 UTC
Policy fixes in https://koji.fedoraproject.org/koji/buildinfo?buildID=1584206


Note You need to log in before you can comment on or make changes to this bug.