Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-66771

[RHEL 10.0] avc: denied { search } for pid=9945 comm="rpc.statd" name="net" dev="proc"

    • Icon: Bug Bug
    • Resolution: Duplicate
    • Icon: Undefined Undefined
    • None
    • rhel-10.0
    • selinux-policy
    • None
    • No
    • None
    • rhel-sst-security-selinux
    • ssg_security
    • None
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • None

      What were you trying to do that didn't work?

      SELinux status:                 enabled
      SELinuxfs mount:                /sys/fs/selinux
      SELinux root directory:         /etc/selinux
      Loaded policy name:             targeted
      Current mode:                   enforcing
      Mode from config file:          enforcing
      Policy MLS status:              enabled
      Policy deny_unknown status:     allowed
      Memory protection checking:     actual (secure)
      Max kernel policy version:      33
      selinux-policy-40.13.12-2.el10.noarch


      time->Fri Nov  8 05:09:46 2024
      type=PROCTITLE msg=audit(1731060586.644:689): proctitle="/usr/sbin/rpc.statd"
      type=SYSCALL msg=audit(1731060586.644:689): arch=c000003e syscall=257 success=no exit=-13 a0=ffffff9c a1=7fffee807fe0 a2=80100 a3=0 items=0 ppid=1 pid=9945 auid=4294967295 uid=29 gid=29 euid=29 suid=29 fsuid=29 egid=29 sgid=29 fsgid=29 tty=(none) ses=4294967295 comm="rpc.statd" exe="/usr/sbin/rpc.statd" subj=system_u:system_r:rpcd_t:s0 key=(null)
      type=AVC msg=audit(1731060586.644:689): avc:  denied  { search } for  pid=9945 comm="rpc.statd" name="net" dev="proc" ino=2299 scontext=system_u:system_r:rpcd_t:s0 tcontext=system_u:object_r:sysctl_net_t:s0 tclass=dir permissive=0

      What is the impact of this issue to you?

      function error

      Please provide the package NVR for which the bug is seen:

      nfs-utils-2.7.1-1.el10

      selinux-policy-40.13.12-2.el10

      How reproducible is this bug?:

      reproducible but random

      Expected results

      No AVC denied for defined operations

      Actual results

      AVC denied

       

      Additional info:
      beaker job:

      https://beaker.engineering.redhat.com/jobs/10155594

      https://beaker-archive.prod.engineering.redhat.com/beaker-logs/2024/11/101555/10155594/17420835/186429968/869982696/avc.log

              rhn-support-zpytela Zdenek Pytela
              rh-ee-yieli Zhi Li
              Zdenek Pytela Zdenek Pytela
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: