-
Story
-
Resolution: Done-Errata
-
Major
-
None
-
NetworkManager-1.46.0-3.el9_4
-
High
-
1
-
rhel-sst-network-management
-
ssg_networking
-
2
-
False
-
-
No
-
NMT - RHEL-9.5 DTM 4
-
Approved Exception
-
None
Nm-cloud-setup systemd unit was changed to include PrivateUsers=yes, and this makes the process start in a different user namespace: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/6fb4af730012441adbbc99e87ae137195d7109a5
This change is causing the avc denial described in RHEL-24346 and as this is a blocker for osbuild-composer testing on AWS on RHEL-9.4, we need to remove the PrivateUsers=yes directive in downstream. selinux team will then allow the permission in selinux-policy during RHEL 9.5 development cycle.
- relates to
-
RHEL-24346 SELinux prevents NetworkManager from using the sys_ptrace capability in user namespaces
- Closed
- links to
-
RHBA-2023:120156 NetworkManager bug fix and enhancement update