Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-88045

SELinux prevents haproxy from mmap-ing /dev/shm/haproxy_startup_logs_* files

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • selinux-policy-38.1.57-1.el9
    • No
    • Low
    • 1
    • rhel-security-selinux
    • ssg_security
    • 15
    • 0.5
    • QE ack
    • False
    • False
    • Hide

      None

      Show
      None
    • No
    • SELINUX 250604: 7
    • Release Note Not Required
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      selinux-policy-38.1.55-1.el9.noarch
      selinux-policy-targeted-38.1.55-1.el9.noarch

      After rebase of haproxy to haproxy-2.8.14-1.el9 for RHEL9 just launching haproxy regardless of config file causes denials like this:

      ----
      time->Tue Apr 15 10:42:44 2025
      type=PROCTITLE msg=audit(1744706564.038:1099): proctitle=2F7573722F7362696E2F686170726F7879002D66002F6574632F686170726F78792F686170726F78792E636667002D66002F6574632F686170726F78792F636F6E662E64002D63002D71
      type=SYSCALL msg=audit(1744706564.038:1099): arch=c000003e syscall=9 success=no exit=-13 a0=0 a1=10000 a2=3 a3=1 items=0 ppid=1 pid=96752 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="haproxy" exe="/usr/sbin/haproxy" subj=system_u:system_r:haproxy_t:s0 key=(null)
      type=AVC msg=audit(1744706564.038:1099): avc:  denied  { map } for  pid=96752 comm="haproxy" path=2F6465762F73686D2F686170726F78795F737461727475705F6C6F67735F3936373532202864656C6574656429 dev="tmpfs" ino=2 scontext=system_u:system_r:haproxy_t:s0 tcontext=system_u:object_r:haproxy_tmpfs_t:s0 tclass=file permissive=0
      

      I checked and the `map` permission for haproxy_tmpfs_t:file is already present in RHEL10.

              rhn-support-zpytela Zdenek Pytela
              jhrdlica Juraj Hrdlica
              Milos Malik Milos Malik
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: