Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-15326

the dhcpcd service triggers { bpf } denials

    • selinux-policy-38.1.28-1.el9
    • None
    • Low
    • sst_security_selinux
    • ssg_security
    • 14
    • None
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      The dhcpcd service starts and runs successfully in enforcing mode. The dhcpcd service does not trigger any SELinux denials in default configuration.

      Show
      The dhcpcd service starts and runs successfully in enforcing mode. The dhcpcd service does not trigger any SELinux denials in default configuration.
    • Pass
    • Automated
    • Release Note Not Required
    • x86_64
    • None

      What were you trying to do that didn't work?

      It seems that the dhcpcd service starts and runs successfully in enforcing mode, but each (re)start of the service triggers several SELinux denials.

      Please provide the package NVR for which bug is seen:

      dhcpcd-10.0.2-7.el9.x86_64
      selinux-policy-38.1.25-1.el9.noarch
      selinux-policy-devel-38.1.25-1.el9.noarch
      selinux-policy-targeted-38.1.25-1.el9.noarch

      How reproducible:

      always

      Steps to reproduce

      1. get a RHEL-9.4 machine (targeted policy is active)
      2. install the dhcpcd package (from EPEL repository)
      3. start the dhcpcd service
      4. search for SELinux denials

      Expected results

      No SELinux denials are triggered.

      Actual results

      ----
      type=PROCTITLE msg=audit(11/02/2023 10:36:03.762:321) : proctitle=dhcpcd: [BPF BOOTP] eth0 
      type=SYSCALL msg=audit(11/02/2023 10:36:03.762:321) : arch=x86_64 syscall=setsockopt success=yes exit=0 a0=0x6 a1=SOL_SOCKET a2=SO_ATTACH_FILTER a3=0x7ffc944ef520 items=0 ppid=9933 pid=10069 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=dhcpcd exe=/usr/sbin/dhcpcd subj=system_u:system_r:dhcpc_t:s0 key=(null) 
      type=AVC msg=audit(11/02/2023 10:36:03.762:321) : avc:  denied  { bpf } for  pid=10069 comm=dhcpcd capability=bpf  scontext=system_u:system_r:dhcpc_t:s0 tcontext=system_u:system_r:dhcpc_t:s0 tclass=capability2 permissive=0 
      ----
      

            rhn-support-zpytela Zdenek Pytela
            mmalik@redhat.com Milos Malik
            Nikola Kňažeková Nikola Kňažeková (Inactive)
            Milos Malik Milos Malik
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

              Created:
              Updated:
              Resolved: