Bug 2456368 - avc: denied { create } for comm="rpc.mountd" scontext=system_u:system_r:nfsd_t:s0 tcontext=system_u:system_r:nfsd_t:s0 tclass=netlink_generic_socket permissive=0
Summary: avc: denied { create } for comm="rpc.mountd" scontext=system_u:system_r:nfsd_...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-08 07:08 UTC by Yongcheng Yang
Modified: 2026-04-08 07:08 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Yongcheng Yang 2026-04-08 07:08:24 UTC
There is a new avc denied warning emit for rpc.mountd when mounting nfs in version 3:
[root@kvm-01-guest02 ~]# >/var/log/audit/audit.log
[root@kvm-01-guest02 ~]# grep denied /var/log/audit/audit.log
[root@kvm-01-guest02 ~]# ./repro.sh
[root@kvm-01-guest02 ~]# grep denied /var/log/audit/audit.log
type=AVC msg=audit(1775631690.243:814): avc:  denied  { create } for  pid=6004 comm="rpc.mountd" scontext=system_u:system_r:nfsd_t:s0 tcontext=system_u:system_r:nfsd_t:s0 tclass=netlink_generic_socket permissive=0
type=AVC msg=audit(1775631690.492:817): avc:  denied  { create } for  pid=6004 comm="rpc.mountd" scontext=system_u:system_r:nfsd_t:s0 tcontext=system_u:system_r:nfsd_t:s0 tclass=netlink_generic_socket permissive=0
[root@kvm-01-guest02 ~]# 
[root@kvm-01-guest02 ~]# cat repro.sh
#!/bin/bash
mkdir -p /export /mnt/localhost

systemctl restart nfs-server

exportfs -ua
exportfs localhost:/export

mount -t nfs -ov3,sec=sys localhost:/export /mnt/localhost
umount /mnt/localhost
[root@kvm-01-guest02 ~]# rpm -q nfs-utils selinux-policy
nfs-utils-2.9.1-0.fc45.x86_64
selinux-policy-43.6-1.fc45.noarch
[root@kvm-01-guest02 ~]#

Reproducible: Always

Steps to Reproduce:
1. export an nfs localhost
2. mounting the export in vers=3
3. check the /var/log/audit/audit.log


Note You need to log in before you can comment on or make changes to this bug.