fedora-selinux / selinux-policy

selinux-policy for Fedora is a large patch off the mainline
GNU General Public License v2.0
156 stars 157 forks source link

Allow NetworkManager the sys_ptrace capability in user namespace #2067

Closed zpytela closed 3 months ago

zpytela commented 3 months ago

The commit addresses the following AVC denial: type=PROCTITLE msg=audit(03/11/2024 06:47:26.478:1051) : proctitle=/usr/sbin/NetworkManager --no-daemon type=SYSCALL msg=audit(03/11/2024 06:47:26.478:1051) : arch=x86_64 syscall=read success=yes exit=185 a0=0x16 a1=0x7ffc1fa820b0 a2=0x1000 a3=0x0 items=0 ppid=1 pid=627 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=NetworkManager exe=/usr/sbin/NetworkManager subj=system_u:system_r:NetworkManager_t:s0 key=(null) type=AVC msg=audit(03/11/2024 06:47:26.478:1051) : avc: denied { sys_ptrace } for pid=627 comm=NetworkManager capability=sys_ptrace scontext=system_u:system_r:NetworkManager_t:s0 tcontext=system_u:system_r:NetworkManager_t:s0 tclass=cap_userns permissive=0

Resolves: RHEL-24346