Bug 2269708 - SELinux prevents the dhcpcd service from reading /run/netns when it exists
Summary: SELinux prevents the dhcpcd service from reading /run/netns when it exists
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 2270733 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-03-15 15:02 UTC by Milos Malik
Modified: 2024-04-14 20:57 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2024-04-14 20:57:47 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2064 0 None open Allow dhcpc read /run/netns files 2024-03-15 15:34:18 UTC

Description Milos Malik 2024-03-15 15:02:32 UTC
The /run/netns directory is created when a new network namespace is created or the 'ip netns monitor' command is executed. The directory remains on filesystem after deleting the network namespace.

Apparently, the dhcpcd program wants to do something with the directory.

# strings `which dhcpcd` | grep /run/netns
/var/run/netns
/var/run/netns/%s
#

Reproducible: Always

Steps to Reproduce:
1. get a Fedora machine (targeted policy is active)
2. # ip netns add test-ns
3. # ip netns del test-ns
4. # service dhcpcd start
5. search for SELinux denials

Actual Results:  
----
type=PROCTITLE msg=audit(03/15/2024 10:52:30.995:633) : proctitle=/usr/sbin/dhcpcd -q --nobackground 
type=PATH msg=audit(03/15/2024 10:52:30.995:633) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(03/15/2024 10:52:30.995:633) : cwd=/ 
type=SYSCALL msg=audit(03/15/2024 10:52:30.995:633) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x55d4418543ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=2900 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) 
type=AVC msg=audit(03/15/2024 10:52:30.995:633) : avc:  denied  { read } for  pid=2900 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=0 
----
type=PROCTITLE msg=audit(03/15/2024 10:52:30.997:634) : proctitle=dhcpcd: [privileged proxy] 
type=PATH msg=audit(03/15/2024 10:52:30.997:634) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(03/15/2024 10:52:30.997:634) : cwd=/ 
type=SYSCALL msg=audit(03/15/2024 10:52:30.997:634) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x55d4418543ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2900 pid=2901 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) 
type=AVC msg=audit(03/15/2024 10:52:30.997:634) : avc:  denied  { read } for  pid=2901 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=0 
----

Expected Results:  
no SELinux denials

dhcpcd-10.0.6-4.fc41.x86_64
selinux-policy-40.13-1.fc40.noarch
selinux-policy-targeted-40.13-1.fc40.noarch

Comment 1 Milos Malik 2024-03-15 15:10:54 UTC
The following SELinux denial appears in permissive mode:
----
type=PROCTITLE msg=audit(03/15/2024 11:08:18.228:673) : proctitle=/usr/sbin/dhcpcd -q --nobackground 
type=PATH msg=audit(03/15/2024 11:08:18.228:673) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 
type=CWD msg=audit(03/15/2024 11:08:18.228:673) : cwd=/ 
type=SYSCALL msg=audit(03/15/2024 11:08:18.228:673) : arch=x86_64 syscall=openat success=yes exit=5 a0=AT_FDCWD a1=0x557631ad03ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=3272 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) 
type=AVC msg=audit(03/15/2024 11:08:18.228:673) : avc:  denied  { read } for  pid=3272 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=1 
----

It does not matter if the /run/netns directory is empty or not. The number of SELinux denials triggered in permissive mode is 1 per restart of the dhcpcd service.

Comment 2 Milos Malik 2024-03-15 15:30:26 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/481

The PR waits for a review.

Comment 3 Zdenek Pytela 2024-03-21 15:32:08 UTC
*** Bug 2270733 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.