Keepalived unconfined script cannot control systemd services
Issue
- Keepalived scripts executing as
keepalived_unconfined_script_t
SELinux domain cannot executesystemctl
commands -
A USER_AVC related to
init_t
andkeepalived_unconfined_script_t
is seen in the audit logtype=USER_AVC msg=audit(01/16/2024 14:39:57.358:4406319) : pid=2242023 uid=dbus auid=unset ses=unset subj=system_u:system_r:system_dbusd_t:s0-s0:c0.c1023 msg='avc: denied { send_msg } for msgtype=method_return dest=:1.856978 spid=1 tpid=325533 scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:keepalived_unconfined_script_t:s0 tclass=dbus permissive=0 exe=/usr/bin/dbus-daemon sauid=dbus hostname=? addr=? terminal=?'
Environment
- Red Hat Enterprise Linux 8
- keepalived
- selinux-policy-3.14.3-128.el8_9.1.noarch
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.