Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-47033

systemd-network-generator.service hitting AVC denials

    • selinux-policy-38.1.44-1.el9
    • None
    • None
    • rhel-sst-security-selinux
    • ssg_security
    • 25
    • None
    • False
    • Hide

      None

      Show
      None
    • No
    • None
    • Hide

      The systemd-network-generator service does not trigger SELinux denials when executed in Stream CoreOS environment.

      Show
      The systemd-network-generator service does not trigger SELinux denials when executed in Stream CoreOS environment.
    • Pass
    • None
    • Unspecified Release Note Type - Unknown
    • None

      What were you trying to do that didn't work?

      Use systemd-network-generator.service in a build of SCOS (Stream CoreOS).

      Please provide the package NVR for which bug is seen:

      selinux-policy-38.1.41-1.el9.noarch (c9s-baseos)

      systemd-252-38.el9.x86_64 (c9s-baseos)

      How reproducible:

      Always

      Steps to reproduce

      1. Build SCOS (using `--variant c9s` (see step 4 in https://coreos.github.io/coreos-assembler/working/#im-a-contributor-investigating-a-coreos-bug-how-can-i-test-my-fixes)
      2. Run e.g. `coreos-assembler kola run ext.config.shared.networking.nameserver`

      Expected results

      Test passes

      Actual results

      Jul 10 15:16:27.352220 kernel: audit: type=1400 audit(1720624587.157:4): avc:  denied  { create } for  pid=1365 comm="systemd-network" name=".#networkLisqyO" scontext=system_u:system_r:systemd_network_generator_t:s0 tcontext=system_u:object_r:init_var_run_t:s0 tclass=file permissive=0

              rhn-support-zpytela Zdenek Pytela
              jlebon1@redhat.com Jonathan Lebon
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated:
                Resolved: