Bug 2366205 - SELinux is preventing nm-vpnc-service from 'execute_no_trans' accesses on the file /usr/bin/consolehelper.
Summary: SELinux is preventing nm-vpnc-service from 'execute_no_trans' accesses on the...
Keywords:
Status: CLOSED DUPLICATE of bug 2366041
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 42
Hardware: x86_64
OS: Unspecified
low
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: abrt_hash:f0b6c7a0d1d8079099dc95c7581...
: 2386603 (view as bug list)
Depends On: 2366041
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-05-14 09:14 UTC by brice
Modified: 2026-04-19 04:25 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2025-12-19 09:30:09 UTC
Type: ---
Embargoed:
zpytela: mirror+


Attachments (Terms of Use)
File: description (2.06 KB, text/plain)
2025-05-14 09:14 UTC, brice
no flags Details
File: os_info (767 bytes, text/plain)
2025-05-14 09:14 UTC, brice
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FC-1662 0 None None None 2025-05-14 14:54:10 UTC

Internal Links: 2360779

Description brice 2025-05-14 09:14:07 UTC
Description of problem:
i was trying to connect to a vpn (using vpnc) using networkmanager
SELinux is preventing nm-vpnc-service from 'execute_no_trans' accesses on the file /usr/bin/consolehelper.

*****  Plugin catchall (100. confidence) suggests   **************************

If you believe that nm-vpnc-service should be allowed execute_no_trans access on the consolehelper file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
# ausearch -c 'nm-vpnc-service' --raw | audit2allow -M my-nmvpncservice
# semodule -X 300 -i my-nmvpncservice.pp

Additional Information:
Source Context                system_u:system_r:NetworkManager_t:s0
Target Context                system_u:object_r:consolehelper_exec_t:s0
Target Objects                /usr/bin/consolehelper [ file ]
Source                        nm-vpnc-service
Source Path                   nm-vpnc-service
Port                          <Unknown>
Host                          (removed)
Source RPM Packages           
Target RPM Packages           usermode-1.114-12.fc42.x86_64
SELinux Policy RPM            selinux-policy-targeted-41.39-1.fc42.noarch
Local Policy RPM              selinux-policy-targeted-41.39-1.fc42.noarch
Selinux Enabled               True
Policy Type                   targeted
Enforcing Mode                Enforcing
Host Name                     (removed)
Platform                      Linux (removed) 6.14.5-300.fc42.x86_64 #1 SMP
                              PREEMPT_DYNAMIC Fri May 2 14:16:46 UTC 2025 x86_64
Alert Count                   2
First Seen                    2025-05-14 11:04:12 CEST
Last Seen                     2025-05-14 11:04:12 CEST
Local ID                      d6c6ac81-673c-42ef-9967-0a4dec35164e

Raw Audit Messages
type=AVC msg=audit(1747213452.399:2347): avc:  denied  { execute_no_trans } for  pid=130565 comm="nm-vpnc-service" path="/usr/bin/consolehelper" dev="dm-0" ino=775699 scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:object_r:consolehelper_exec_t:s0 tclass=file permissive=0


Hash: nm-vpnc-service,NetworkManager_t,consolehelper_exec_t,file,execute_no_trans

Version-Release number of selected component:
selinux-policy-targeted-41.39-1.fc42.noarch

Additional info:
reporter:       libreport-2.17.15
reason:         SELinux is preventing nm-vpnc-service from 'execute_no_trans' accesses on the file /usr/bin/consolehelper.
package:        selinux-policy-targeted-41.39-1.fc42.noarch
component:      selinux-policy
hashmarkername: setroubleshoot
type:           libreport
kernel:         6.14.5-300.fc42.x86_64
comment:        i was trying to connect to a vpn (using vpnc) using networkmanager
component:      selinux-policy

Comment 1 brice 2025-05-14 09:14:10 UTC
Created attachment 2089741 [details]
File: description

Comment 2 brice 2025-05-14 09:14:12 UTC
Created attachment 2089742 [details]
File: os_info

Comment 3 Klaas Weyermann 2025-05-29 09:56:58 UTC
I guess this duplicates https://bugzilla.redhat.com/show_bug.cgi?id=2366041 ?

Comment 4 Zdenek Pytela 2025-06-13 21:00:52 UTC
Can you try the coprbuilds in
https://github.com/fedora-selinux/selinux-policy/pull/2729/checks
to see if anything else is needed?

Comment 5 Zdenek Pytela 2025-08-07 13:17:35 UTC
*** Bug 2386603 has been marked as a duplicate of this bug. ***

Comment 6 Sergio Pascual 2025-11-26 08:54:37 UTC
This is happening also in F43 with selinux-policy-targeted-42.16-1.fc43.noarch

Comment 7 jjanasek 2025-12-19 09:30:09 UTC

*** This bug has been marked as a duplicate of bug 2366041 ***

Comment 8 Red Hat Bugzilla 2026-04-19 04:25:03 UTC
The needinfo request[s] on this closed bug have been removed as they have been unresolved for 120 days or the product is inactive and locked


Note You need to log in before you can comment on or make changes to this bug.