Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-136495

pasta selinux policy prevents podman user container networking

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Blocker Blocker
    • rhel-10.2
    • CentOS Stream 10
    • passt
    • None
    • passt-0^20251210.gd04c480-2.el10
    • Yes
    • Critical
    • 1
    • rhel-virt-networking-passt-pasta
    • 5
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • VIRT-PASST-CY25-Dec-22-Sprint4
    • Unspecified
    • Unspecified
    • Unspecified
    • x86_64
    • None

      What were you trying to do that didn't work?

       

      Tried to restart user container with selinux quadlet after passt upgrade

      What is the impact of this issue to you?

       

      Containers fail to start

      Please provide the package NVR for which the bug is seen:

       

      passt-selinux-0^20251210.gd04c480-1.el10

      How reproducible is this bug?:

       

      Always.

      Steps to reproduce

      1.  sudo dnf upgrade passt
      2.  sudo machinectl shell user@
      3. systemctl --user restart usercontainer.service

      Expected results

       

      Successfull restarted usercontainer.service

      Actual results

       

      After sudo setenforce 0 restart works with these AVCs:

      type=AVC msg=audit(1765925816.168:248726): avc:  denied  { read } for  pid=3149539 comm="pasta.avx2" name="netns" dev="tmpfs" ino=50 scontext=unconfined_u:unconfined_r:pasta_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=dir permissive=1
      type=AVC msg=audit(1765925816.168:248727): avc:  denied  { watch } for  pid=3149539 comm="pasta.avx2" path="/run/user/1005/netns" dev="tmpfs" ino=50 scontext=unconfined_u:unconfined_r:pasta_t:s0-s0:c0.c1023 tcontext=unconfined_u:object_r:user_tmp_t:s0 tclass=dir permissive=1
      

      With selinux enforcing container fail to start.

              rhn-support-leiyang Lei Yang
              bleve Tuomo Soini
              Stefano Brivio Stefano Brivio
              Lei Yang Lei Yang
              Votes:
              0 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated: