Fedora Account System
Red Hat Associate
Red Hat Customer
The /run/netns directory is created when a new network namespace is created or the 'ip netns monitor' command is executed. The directory remains on filesystem after deleting the network namespace. Apparently, the dhcpcd program wants to do something with the directory. # strings `which dhcpcd` | grep /run/netns /var/run/netns /var/run/netns/%s # Reproducible: Always Steps to Reproduce: 1. get a Fedora machine (targeted policy is active) 2. # ip netns add test-ns 3. # ip netns del test-ns 4. # service dhcpcd start 5. search for SELinux denials Actual Results: ---- type=PROCTITLE msg=audit(03/15/2024 10:52:30.995:633) : proctitle=/usr/sbin/dhcpcd -q --nobackground type=PATH msg=audit(03/15/2024 10:52:30.995:633) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(03/15/2024 10:52:30.995:633) : cwd=/ type=SYSCALL msg=audit(03/15/2024 10:52:30.995:633) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x55d4418543ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=2900 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) type=AVC msg=audit(03/15/2024 10:52:30.995:633) : avc: denied { read } for pid=2900 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=0 ---- type=PROCTITLE msg=audit(03/15/2024 10:52:30.997:634) : proctitle=dhcpcd: [privileged proxy] type=PATH msg=audit(03/15/2024 10:52:30.997:634) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(03/15/2024 10:52:30.997:634) : cwd=/ type=SYSCALL msg=audit(03/15/2024 10:52:30.997:634) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x55d4418543ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=2900 pid=2901 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) type=AVC msg=audit(03/15/2024 10:52:30.997:634) : avc: denied { read } for pid=2901 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=0 ---- Expected Results: no SELinux denials dhcpcd-10.0.6-4.fc41.x86_64 selinux-policy-40.13-1.fc40.noarch selinux-policy-targeted-40.13-1.fc40.noarch
The following SELinux denial appears in permissive mode: ---- type=PROCTITLE msg=audit(03/15/2024 11:08:18.228:673) : proctitle=/usr/sbin/dhcpcd -q --nobackground type=PATH msg=audit(03/15/2024 11:08:18.228:673) : item=0 name=/var/run/netns inode=1401 dev=00:19 mode=dir,755 ouid=root ogid=root rdev=00:00 obj=unconfined_u:object_r:ifconfig_var_run_t:s0 nametype=NORMAL cap_fp=none cap_fi=none cap_fe=0 cap_fver=0 cap_frootid=0 type=CWD msg=audit(03/15/2024 11:08:18.228:673) : cwd=/ type=SYSCALL msg=audit(03/15/2024 11:08:18.228:673) : arch=x86_64 syscall=openat success=yes exit=5 a0=AT_FDCWD a1=0x557631ad03ae a2=O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC a3=0x0 items=1 ppid=1 pid=3272 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) type=AVC msg=audit(03/15/2024 11:08:18.228:673) : avc: denied { read } for pid=3272 comm=dhcpcd name=netns dev="tmpfs" ino=1401 scontext=system_u:system_r:dhcpc_t:s0 tcontext=unconfined_u:object_r:ifconfig_var_run_t:s0 tclass=dir permissive=1 ---- It does not matter if the /run/netns directory is empty or not. The number of SELinux denials triggered in permissive mode is 1 per restart of the dhcpcd service.
Test coverage for this bug exists in a form of PR: * https://src.fedoraproject.org/tests/selinux/pull-request/481 The PR waits for a review.
*** Bug 2270733 has been marked as a duplicate of this bug. ***