Bug 2366041 - selinux denials since f42 [NEEDINFO]
Summary: selinux denials since f42
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 44
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
: 2366205 (view as bug list)
Depends On:
Blocks: 2366205
TreeView+ depends on / blocked
 
Reported: 2025-05-13 18:36 UTC by Klaas Weyermann
Modified: 2026-08-30 09:54 UTC (History)
19 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-06-09 11:15:56 UTC
Type: ---
Embargoed:
klaas: needinfo? (zpytela)
klaas: needinfo? (zpytela)
zpytela: mirror+


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github fedora-selinux selinux-policy pull 2729 0 None open Allow NetworkManager execute consolehelper and userhelper 2025-06-11 14:37:35 UTC
Red Hat Bugzilla 2363531 0 unspecified CLOSED vpnc just exists with "Unknown error" (255) every single time. 2025-05-15 18:44:44 UTC
Red Hat Issue Tracker FC-1704 0 None None None 2025-05-29 17:37:44 UTC

Internal Links: 2360779 2363531

Description Klaas Weyermann 2025-05-13 18:36:18 UTC
Hi,
it seems that since f42 vpnc was changed to use consolehelper, this produces selinux denials when used with NetworkManager-vpnc

Setting selinux to permissive produces a working vpn connection, the logged denials are the following:


May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { execute } for  pid=15722 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { read open } for  pid=15722 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { execute_no_trans } for  pid=15722 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { map } for  pid=15722 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { execute } for  pid=15722 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { read open } for  pid=15722 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { execute_no_trans } for  pid=15722 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { map } for  pid=15722 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { read write } for  pid=15722 comm="userhelper" name="vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { open } for  pid=15722 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { getattr } for  pid=15722 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15722]: AVC avc:  denied  { compute_av } for  pid=15722 comm="userhelper" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:security_t:s0 tclass=security permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { execute } for  pid=15732 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { read open } for  pid=15732 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { execute_no_trans } for  pid=15732 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { map } for  pid=15732 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { execute } for  pid=15732 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { read open } for  pid=15732 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { execute_no_trans } for  pid=15732 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: AVC avc:  denied  { map } for  pid=15732 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
May 13 20:10:58 hostname.tld audit[15732]: USER_AVC pid=15732 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:NetworkManager_t:s0 msg='avc:  denied  { rootok } for  scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:system_r:NetworkManager_t:s0 tclass=passwd permissive=1 exe="/usr/bin/userhelper" sauid=0 hostname=? addr=? terminal=?'



Reproducible: Always

Steps to Reproduce:
1. have a vpnc VPN connection managed by NetworkManager
2. connect to it
3.
Actual Results:
Not working

Expected Results:
Working

Comment 1 Christian Krause 2025-05-15 22:36:50 UTC
The SELinux policies for vpnc seem to be in the selinux-policy package.

Some background why this problem happens now: due to the /usr/(s)bin merge, the vpnc package was slightly re-structured to always use consolehelper - even when called as root (as done by NetworkManager as well).

The vpnc binary can be called as follows:
- as root
- as unprivileged user
- via parametrized systemd unit (as root)
- by NetworkManager (called as root)

Which exact debug information do you need in order to fix the SELinux policies for all of these cases?

Comment 2 Zdenek Pytela 2025-06-12 18:59:10 UTC
Can you try the coprbuilds in
https://github.com/fedora-selinux/selinux-policy/pull/2729/checks
to see if anything else is needed?

Comment 3 Klaas Weyermann 2025-06-16 19:16:44 UTC
Hi,
sorry it took me a while to get back to you. With this policy I still do not get a working vpn connection. When running in permissive I get the following denials:

Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { execute } for  pid=4233 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { read open } for  pid=4233 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { execute_no_trans } for  pid=4233 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { map } for  pid=4233 comm="vpnc" path="/usr/bin/consolehelper" dev="dm-0" ino=5491504 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { execute } for  pid=4233 comm="vpnc" name="userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { read open } for  pid=4233 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { execute_no_trans } for  pid=4233 comm="vpnc" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { map } for  pid=4233 comm="userhelper" path="/usr/bin/userhelper" dev="dm-0" ino=5491505 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_exec_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { read write } for  pid=4233 comm="userhelper" name="vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { open } for  pid=4233 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4233]: AVC avc:  denied  { getattr } for  pid=4233 comm="userhelper" path="/etc/security/console.apps/vpnc" dev="dm-0" ino=5793166 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:userhelper_conf_t:s0 tclass=file permissive=1
Jun 16 21:05:39 hostname.tld audit[4243]: AVC avc:  denied  { compute_av } for  pid=4243 comm="userhelper" scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:security_t:s0 tclass=security permissive=1


selinux-policy-41.43-1.20250611190034417930.pr2729.8.g8e7039c7f.fc42.noarch
selinux-policy-targeted-41.43-1.20250611190034417930.pr2729.8.g8e7039c7f.fc42.noarch

Comment 4 jjanasek 2025-12-19 09:30:09 UTC
*** Bug 2366205 has been marked as a duplicate of this bug. ***

Comment 5 rhbug 2026-01-20 12:30:07 UTC
FWIW, I can get it to work using these permissions:

module my-vpnc 1.0;

require {
	type consolehelper_exec_t;
	type userhelper_conf_t;
	type userhelper_exec_t;
	type security_t;
	type NetworkManager_t;
	type chkpwd_exec_t;
	class file { execute execute_no_trans getattr map open read write };
	class dir search;
	class security compute_av;
	class passwd rootok;
}

#============= NetworkManager_t ==============

allow NetworkManager_t chkpwd_exec_t:file execute;
allow NetworkManager_t consolehelper_exec_t:file { execute execute_no_trans map open read };
allow NetworkManager_t security_t:security compute_av;
allow NetworkManager_t self:passwd rootok;
allow NetworkManager_t userhelper_conf_t:dir search;
allow NetworkManager_t userhelper_conf_t:file { getattr open read write };
allow NetworkManager_t userhelper_exec_t:file { execute execute_no_trans map open read };


Save the above type enforcements as my-vpnc.te and run the following commands:

# checkmodule -Mmo my-vpnc.mod my-vpnc.te
# semodule_package -o my-vpnc.pp -m my-vpnc.mod
# semodule -i my-vpnc.pp

This should persist through reboots, to revert run:
# semodule -r my-vpnc

One issue that remained is that the vpnc client keeps running when I stop the VPN through NetworkManager, but I'm not sure that is selinux related. This may prevent you from reconnecting because the interface stays in use.

To stop vpnc manually, run:
# pkill vpnc

Comment 6 Fedora Release Engineering 2026-05-06 12:55:16 UTC
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, change the 'version' 
to a later Fedora Linux version. Note that the version field may be hidden.
Click the "Show advanced fields" button if you do not see it.

Thank you for reporting this issue and we are sorry that we were not 
able to fix it before Fedora Linux 42 is end of life. If you would still like 
to see this bug fixed and are able to reproduce it against a later version 
of Fedora Linux, you are encouraged to change the 'version' to a later version
prior to this bug being closed.

Comment 7 Yann Soubeyrand 2026-05-06 13:20:12 UTC
Hi,

This bug is still present on Fedora 44:

```
type=AVC msg=audit(1778073518.929:409): avc:  denied  { execute } for  pid=86774 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1987 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0
type=AVC msg=audit(1778073518.994:410): avc:  denied  { execute } for  pid=86781 comm="nm-vpnc-service" name="consolehelper" dev="overlay" ino=1987 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0
```

Comment 8 Aoife Moloney 2026-06-08 17:07:45 UTC
Fedora Linux 42 entered end-of-life (EOL) status on 2026-05-27.

Fedora Linux 42 is no longer maintained, which means that it
will not receive any further security or bug fix updates. As a result we
are closing this bug.

If you can reproduce this bug against a currently maintained version of Fedora Linux
please feel free to reopen this bug against that version. Note that the version
field may be hidden. Click the "Show advanced fields" button if you do not see
the version field.

If you are unable to reopen this bug, please file a new report against an
active release.

Thank you for reporting this bug and we are sorry it could not be fixed.

Comment 9 Yann Soubeyrand 2026-06-08 20:14:27 UTC
Hi,

Could this issue be re-opened please? Fedora 44 is still affected.

Regards

Comment 10 Klaas Weyermann 2026-06-08 20:46:53 UTC
I can't seem to edit the version, I could only reopen it; @zpytela can you change it for us?

Comment 11 Aoife Moloney 2026-06-09 11:15:56 UTC
Fedora Linux 42 entered end-of-life (EOL) status on 2026-05-27.

Fedora Linux 42 is no longer maintained, which means that it
will not receive any further security or bug fix updates. As a result we
are closing this bug.

If you can reproduce this bug against a currently maintained version of Fedora Linux
please feel free to reopen this bug against that version. Note that the version
field may be hidden. Click the "Show advanced fields" button if you do not see
the version field.

If you are unable to reopen this bug, please file a new report against an
active release.

Thank you for reporting this bug and we are sorry it could not be fixed.

Comment 12 Christian Krause 2026-06-09 20:53:03 UTC
Re-opening again. I set the Fedora version to 44 according to comment #9.

At first, I didn't find the option to set the version either. After some searching: it is hidden by default in the edit view but there is a button "Show advanced fields" which makes it visible.

Comment 13 lemmingnr13 2026-08-30 09:54:20 UTC
Got the same on Fedora Sway Spin (44). This is after a fresh install, trying to connect a newly created VPNC connection via Networkmanager. I am very new to SELinux so I can only provide the information I gathered by following this guide: https://docs.fedoraproject.org/en-US/quick-docs/selinux-troubleshooting/

>> journalctl -t setroubleshoot:

Aug 29 20:26:05 tuxedo setroubleshoot[69065]: SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper. For complete SELinux messages run: sea>
Aug 29 20:26:05 tuxedo setroubleshoot[69065]: SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper.

>> sealert -l "*" SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper.

SELinux is preventing nm-vpnc-service from execute access on the file /usr/bin/consolehelper.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that nm-vpnc-service should be allowed execute access on the consolehelper file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'nm-vpnc-service' --raw | audit2allow -M my-nmvpncservice
# semodule -X 300 -i my-nmvpncservice.pp


Additional Information:
Source Context                system_u:system_r:NetworkManager_t:s0
Target Context                system_u:object_r:consolehelper_exec_t:s0
Target Objects                /usr/bin/consolehelper [ file ]
Source                        nm-vpnc-service
Source Path                   nm-vpnc-service
Port                          <Unknown>
Host                          tuxedo
Source RPM Packages           
Target RPM Packages           usermode-1.114-16.fc44.x86_64
SELinux Policy RPM            selinux-policy-targeted-44.7-1.fc44.noarch
Local Policy RPM              selinux-policy-targeted-44.7-1.fc44.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     tuxedo
Platform                      Linux tuxedo 7.1.10-200.fc44.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Sun Aug 23 16:15:11 UTC 2026
                              x86_64
Alert Count                   5
First Seen                    2026-08-29 20:25:46 CEST
Last Seen                     2026-08-30 11:06:46 CEST
Local ID                      36ff4508-4761-4e43-89b9-f9d04d54c2c4

Raw Audit Messages
type=AVC msg=audit(1788080806.814:244): avc:  denied  { execute } for  pid=10703 comm="nm-vpnc-service" name="consolehelper" dev="dm-0" ino=8401 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0


Hash: nm-vpnc-service,NetworkManager_t,consolehelper_exec_t,file,execute


Note You need to log in before you can comment on or make changes to this bug.