Bug 834643 - AVC's of NetworkManager-openvpn
AVC's of NetworkManager-openvpn
Status: CLOSED NOTABUG
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: selinux-policy (Show other bugs)
6.3
All Linux
low Severity low
: beta
: 6.4
Assigned To: Miroslav Grepl
BaseOS QE Security Team
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2012-06-22 12:14 EDT by David Jaša
Modified: 2012-06-25 06:56 EDT (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2012-06-25 06:56:04 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description David Jaša 2012-06-22 12:14:49 EDT
Description of problem:


Version-Release number of selected component (if applicable):
NetworkManager-0.8.1-33.el6.x86_64
NetworkManager-openvpn-0.8.1-0.1.git20100609.el6.x86_64
wpa_supplicant-0.7.3-3.el6.x86_64
selinux-policy-3.7.19-154.el6.noarch
RHEL 6.3

How reproducible:
always

Steps to Reproduce:
1. connect to an openvpn gateway
2.
3.
  
Actual results:
I'm getting AVCs below in /var/log/messages (audit/audit.log is silent)

Expected results:
no AVCs

Additional info:
# tail -fn0 /var/log/messages | grep -i avc
Jun 22 18:07:35 dhcp-29-7 kernel: type=1400 audit(1340381255.140:107714): avc:  denied  { rlimitinh } for  pid=5273 comm="modprobe" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:insmod_t:s0 tclass=process
Jun 22 18:07:35 dhcp-29-7 kernel: type=1400 audit(1340381255.140:107715): avc:  denied  { siginh } for  pid=5273 comm="modprobe" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:insmod_t:s0 tclass=process
Jun 22 18:07:35 dhcp-29-7 kernel: type=1400 audit(1340381255.140:107716): avc:  denied  { noatsecure } for  pid=5273 comm="modprobe" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:insmod_t:s0 tclass=process
// right after dialog appeared
Jun 22 18:08:07 dhcp-29-7 kernel: type=1400 audit(1340381287.511:107717): avc:  denied  { rlimitinh } for  pid=5276 comm="openvpn" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:openvpn_t:s0 tclass=process
Jun 22 18:08:07 dhcp-29-7 kernel: type=1400 audit(1340381287.511:107718): avc:  denied  { siginh } for  pid=5276 comm="openvpn" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:openvpn_t:s0 tclass=process
Jun 22 18:08:07 dhcp-29-7 kernel: type=1400 audit(1340381287.511:107719): avc:  denied  { noatsecure } for  pid=5276 comm="openvpn" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:openvpn_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.738:107720): avc:  denied  { rlimitinh } for  pid=5284 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:initrc_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.738:107721): avc:  denied  { siginh } for  pid=5284 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:initrc_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.738:107722): avc:  denied  { noatsecure } for  pid=5284 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:initrc_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.753:107723): avc:  denied  { rlimitinh } for  pid=5287 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:nscd_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.753:107724): avc:  denied  { siginh } for  pid=5287 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:nscd_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.753:107725): avc:  denied  { noatsecure } for  pid=5287 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:nscd_t:s0 tclass=process
Jun 22 18:08:11 dhcp-29-7 kernel: type=1400 audit(1340381291.756:107726): avc:  denied  { rlimitinh } for  pid=5288 comm="nscd" scontext=unconfined_u:system_r:NetworkManager_t:s0 tcontext=unconfined_u:system_r:initrc_t:s0 tclass=process
// connected
Comment 2 David Jaša 2012-06-22 12:21:24 EDT
Just forgot to add version of openvpn itself:
openvpn-2.2.1-1.el6.x86_64

NM-openvpn is from EPEL.
Comment 3 Miroslav Grepl 2012-06-22 12:21:54 EDT
You turned off dontaudit rules.

# semodule -B
Comment 4 David Jaša 2012-06-22 12:44:47 EDT
Ah, after 'semodule -B', the avc's are gone.

It reappears again when I run 'semodule -DB', which I got left from https://bugzilla.redhat.com/show_bug.cgi?id=823601#c2 .

'ausearch -m avc -ts recent' says just '<no matches>' and two empty lines.
Comment 5 Milos Malik 2012-06-25 03:01:43 EDT
This looks like not a bug to me.

Note You need to log in before you can comment on or make changes to this bug.