Bug 2507305 - SELinux prevents cifs.upcall (cifs_helper_t) from using winbind and Kerberos FILE ccache; multiuser CIFS mounts fail with -126
Summary: SELinux prevents cifs.upcall (cifs_helper_t) from using winbind and Kerberos ...
Keywords:
Status: ASSIGNED
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: rawhide
Hardware: All
OS: Linux
unspecified
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-25 13:19 UTC by Joerg
Modified: 2026-09-04 05:23 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Joerg 2026-07-25 13:19:48 UTC
## Environment

- Distribution: **Rocky Linux 10** (EL10 rebuild) (I filed this against fedora as I believe the change needs to be introduced here first)
- SELinux: enforcing, targeted policy
- Stack: AD domain member via **realmd/winbind**, CIFS mount with **`sec=krb5,multiuser`**, credentials via **`cifs.upcall`** / `request-key`
- Kerberos ccache: `FILE:/tmp/krb5cc_<uid>` (created by pam_winbind at login)
- Boolean already enabled: `use_samba_home_dirs --> on` (does **not** fix this)
- `sesearch -A -s cifs_helper_t -t winbind_var_run_t` → **no allow rules**
- No suitable boolean among `getsebool -a | grep -iE 'cifs|winbind|samba'`

```text
selinux-policy version:
- selinux-policy-42.1.18-4.el10.noarch
- selinux-policy-targeted-42.1.18-4.el10.noarch

cifs-utils version:
cifs-utils-7.6-2.el10_2.x86_64

kernel version:
6.12.0-211.16.1.el10_2.0.1.x86_64

samba-winbind version:
samba-winbind-4.23.5-109.el10_2.x86_64
```

## Summary

On a Rocky Linux 10 AD client, a CIFS share mounted with Kerberos and **`multiuser`** appears mounted (machine-account session works for root on the share root), but domain users get **`Permission denied`** when accessing the mount. Kernel logs show:

```text
CIFS: VFS: \\<server> failed to create a new SMB session with Kerberos: -126
```

(`-126` = `ENOKEY` / “Required key not available”.)

`setenforce 0` makes user access work immediately. Userspace Kerberos to the same share works (`kvno cifs/<server>`, `smbclient --use-kerberos=required`). The failure is confined to the **kernel CIFS + cifs.upcall** path under SELinux enforcing.

Reproducible: Always

Steps to Reproduce:
1. Join Rocky Linux 10 to an Active Directory domain with winbind (e.g. `realm join`, winbind NSS/PAM).
2. Ensure `cifs-utils` is installed and `/etc/request-key.d/cifs.spnego.conf` points at `/usr/sbin/cifs.upcall`.
3. Mount a share, e.g. in `/etc/fstab`:

   ```fstab
   //fileserver.example.net/users  /mnt/users  cifs  \
     sec=krb5,multiuser,cruid=0,user=CLIENTHOST$,vers=3.1.1,\
     _netdev,nofail,x-systemd.automount  0  0
   ```

   (Host-specific `user=<NETBIOS>$` from `/etc/krb5.keytab`. Do **not** use `upcall_target=mount` with `multiuser` – the kernel rejects that combination.)

4. Log in as an AD user; confirm `klist` shows a TGT (`FILE:/tmp/krb5cc_<uid>`).
5. As that user: `ls /mnt/users` (or the chosen mountpoint).
6. Observe `Permission denied`; as root: `dmesg` shows Kerberos session **-126**.
7. `ausearch -m avc -ts recent` shows denials for `comm="cifs.upcall"` / `cifs_helper_t` (see below).
8. `setenforce 0` and repeat step 5 → access succeeds (same mount, same tickets).
Actual Results:
- Root can use the mount via the machine-account session (share root listing may work).
- AD users cannot open the mount (`Permission denied`).
- Kernel: `failed to create a new SMB session with Kerberos: -126`.
- AVC denials for `cifs_helper_t` against winbind runtime socket and Kerberos FILE ccache.

Expected Results:
`cifs.upcall` running as `cifs_helper_t` should be allowed to:

1. Talk to winbind (`/run/samba/winbindd/pipe`) for ID mapping / helper lookups used by multiuser mounts.
2. Open the user’s Kerberos FILE ccache (`user_tmp_t`, e.g. `/tmp/krb5cc_<uid>`).
3. Perform necessary userdb lookups (`systemd_userdbd_runtime_t`) if required by the helper.

Then multiuser CIFS + Kerberos + Winbind should work with SELinux **enforcing**, without a per-host local policy module.

Additional Information:
## AVC evidence (enforcing / permissive)

### Blocking (permissive=0)

```text
avc:  denied  { getattr } for  comm="cifs.upcall" path="/run/samba/winbindd/pipe"
  scontext=system_u:system_r:cifs_helper_t:s0
  tcontext=system_u:object_r:winbind_var_run_t:s0
  tclass=sock_file permissive=0
```

### Additional denials visible under permissive=1 (needed for full success)

```text
avc:  denied  { connectto } for  comm="cifs.upcall" path="/run/samba/winbindd/pipe"
  scontext=system_u:system_r:cifs_helper_t:s0
  tcontext=system_u:system_r:winbind_t:s0
  tclass=unix_stream_socket permissive=1

avc:  denied  { write } for  comm="cifs.upcall" name="pipe"
  scontext=system_u:system_r:cifs_helper_t:s0
  tcontext=system_u:object_r:winbind_var_run_t:s0
  tclass=sock_file permissive=1

avc:  denied  { open } for  comm="cifs.upcall" path="/tmp/krb5cc_2001103"
  scontext=system_u:system_r:cifs_helper_t:s0
  tcontext=system_u:object_r:user_tmp_t:s0
  tclass=file permissive=1

avc:  denied  { read } for  comm="cifs.upcall" name="userdb"
  scontext=system_u:system_r:cifs_helper_t:s0
  tcontext=system_u:object_r:systemd_userdbd_runtime_t:s0
  tclass=dir permissive=1
```

### Minimal local workaround module (for illustration only)

```te
module cifs_upcall_local 1.0;

require {
        type systemd_userdbd_runtime_t;
        type user_tmp_t;
        type cifs_helper_t;
        type winbind_t;
        type winbind_var_run_t;
        class sock_file { getattr write };
        class dir read;
        class unix_stream_socket connectto;
        class file open;
}

#============= cifs_helper_t ==============
allow cifs_helper_t systemd_userdbd_runtime_t:dir read;
allow cifs_helper_t user_tmp_t:file open;
allow cifs_helper_t winbind_t:unix_stream_socket connectto;
allow cifs_helper_t winbind_var_run_t:sock_file { getattr write };
```

(Prefer fixing this in `selinux-policy` rather than requiring sites to ship local modules at scale.)

## Counterchecks already done

- `smbclient --use-kerberos=required //server/share` as the AD user: **works** (userspace Kerberos OK).
- `kvno cifs/<server>@REALM`: **works**; ticket present in FILE ccache.
- `use_samba_home_dirs` on: **does not** resolve the upcall denials (mount under `/home` is a separate concern).
- No boolean enables `cifs_helper_t` → `winbind_var_run_t`.
- `upcall_target=mount` + `multiuser` is rejected by the kernel (`multiuser mount option not supported with upcalltarget set as 'mount'`) – not a viable workaround.

## Impact

Any EL10-based AD client using **documented** CIFS multiuser mounts with Kerberos and Winbind cannot grant domain users access under SELinux enforcing without a custom policy module. This affects enterprise rollouts (hundreds of clients) and forces either permissive mode, local modules, or abandoning multiuser CIFS.

## Requested fix

Please extend the targeted policy so `cifs_helper_t` (`/usr/sbin/cifs.upcall`) can perform the accesses above when using Kerberos FILE ccaches and Winbind on domain-joined hosts—or document an official, scalable boolean/interface if that is the preferred design. A fix in Fedora/`selinux-policy` that rolls into CentOS Stream / RHEL 10 / Rocky 10 is preferred.

If you like me to reproduce this on some some other version, e.g. Rawhide, Centos 10 Strea, etc. please let me know. I'm happy to help.

Comment 1 Joerg 2026-07-25 13:22:14 UTC
Related historical reports exist, but **none match this exact failure mode** (open and applicable to current EL10/Rocky 10):

| Tracker | ID | Status | Relevance |
|---------|-----|--------|-----------|
| RH Bugzilla | [2180634](https://bugzilla.redhat.com/show_bug.cgi?id=2180634) | CLOSED (fixed F38) | Kerberos/SSSD config access for cifs helper – different AVCs |
| RH Bugzilla | [2182643](https://bugzilla.redhat.com/show_bug.cgi?id=2182643) | CLOSED (fixed F38) | `request-key` / keyutils executing `cifs.upcall` |
| RH Bugzilla | [2188074](https://bugzilla.redhat.com/show_bug.cgi?id=2188074) | CLOSED DUPLICATE of 2182643 | Generic “cifs.upcall blocked” |
| RH Bugzilla | [1868966](https://bugzilla.redhat.com/show_bug.cgi?id=1868966) | CLOSED | Winbind pipe denials for **other** domains (`ntlm_auth` etc.), not `cifs_helper_t` |
| GitHub fedora-selinux/selinux-policy | search `cifs_helper` / `cifs.upcall` + `winbind` | **no open hits** | No current issue for this combo |

Best regards,
Joerg


Note You need to log in before you can comment on or make changes to this bug.