[PATCH] udev: allow udevadmin to extend socket recv buffer

Bhabu Bindu <[email protected]> Wed, 14 Jan 2026 09:43:07 +0000
Newsgroups org.kernel.vger.selinux-refpolicy,org.kernel.vger.selinux
Message-ID <MA0PR01MB97933ED6DCFEADB1CB62BDB3958FA@MA0PR01MB9793.INDPRD01.PROD.OUTLOOK.COM>
--_004_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_
Content-Type: multipart/alternative;
	boundary="_000_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_"

--_000_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Hello,

Udevadm-trigger and sd-device-monitor unconditionally increase the receive =
buffer size on netlink sockets. This helps avoid failures under high event =
loads, as below:
wait-for-udev: Failed to increase receive buffer size, ignoring: Operation =
not permitted

To address this, we need to allow udevadm to increase the buffer.
This may fix the issue that udevadm trigger hangs while processing the even=
ts
References:
- https://github.com/systemd/systemd/pull/29872

To support this in SELinux, this patch allows udevadm to use CAP_NET_ADMIN =
to extend
the socket receive buffer to hold more events.

Please review.

Regards,
Bhabu Bindu
This message contains information that may be privileged or confidential an=
d is the property of the KPIT Technologies Ltd. It is intended only for the=
 person to whom it is addressed. If you are not the intended recipient, you=
 are not authorized to read, print, retain copy, disseminate, distribute, o=
r use this message or any part thereof. If you receive this message in erro=
r, please notify the sender immediately and delete all copies of this messa=
ge. KPIT Technologies Ltd. does not accept any liability for virus infected=
 mails.

--_000_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html>
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<style type=3D"text/css" style=3D"display:none;"> P {margin-top:0;margin-bo=
ttom:0;} </style>
</head>
<body dir=3D"ltr">
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Hello,</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Udevadm-trigger and sd-device-monitor unconditionally increase the receive =
buffer size on netlink sockets. This helps avoid failures under high event =
loads, as below:</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
wait-for-udev: Failed to increase receive buffer size, ignoring: Operation =
not permitted</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
To address this, we need to allow udevadm to increase the buffer.</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
This may fix the issue that udevadm trigger hangs while processing the even=
ts</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
References:</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
- https://github.com/systemd/systemd/pull/29872</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
To support this in SELinux, this patch allows udevadm to use CAP_NET_ADMIN =
to extend</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
the socket receive buffer to hold more events.</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
<br>
</div>
<div style=3D"font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, =
Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" clas=
s=3D"elementToProof">
Please review.<br>
<br>
Regards,<br>
Bhabu Bindu</div>
This message contains information that may be privileged or confidential an=
d is the property of the KPIT Technologies Ltd. It is intended only for the=
 person to whom it is addressed. If you are not the intended recipient, you=
 are not authorized to read, print,
 retain copy, disseminate, distribute, or use this message or any part ther=
eof. If you receive this message in error, please notify the sender immedia=
tely and delete all copies of this message. KPIT Technologies Ltd. does not=
 accept any liability for virus
 infected mails.
</body>
</html>

--_000_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_--

--_004_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_
Content-Type: text/x-patch;
	name="0001-udev-allow-udevadmin-to-extend-socket-recv-buffer.patch"
Content-Description:
 0001-udev-allow-udevadmin-to-extend-socket-recv-buffer.patch
Content-Disposition: attachment;
	filename="0001-udev-allow-udevadmin-to-extend-socket-recv-buffer.patch";
	size=1556; creation-date="Wed, 14 Jan 2026 09:42:57 GMT";
	modification-date="Wed, 14 Jan 2026 09:43:07 GMT"
Content-Transfer-Encoding: base64

RnJvbSAyN2VjZWIxNzk3ZTJhYTk0ODQ5OGIwZDI0MzQ5NzlhODFhYWI5N2E5IE1vbiBTZXAgMTcg
MDA6MDA6MDAgMjAwMQpGcm9tOiBCaGFidSBCaW5kdSA8QmhhYnUuQmluZHVAa3BpdC5jb20+CkRh
dGU6IFdlZCwgMTQgSmFuIDIwMjYgMTQ6MTY6MzYgKzA1MzAKU3ViamVjdDogW1BBVENIXSB1ZGV2
OiBhbGxvdyB1ZGV2YWRtaW4gdG8gZXh0ZW5kIHNvY2tldCByZWN2IGJ1ZmZlcgoKVXBzdHJlYW0g
c3lzdGVtZCBjb21taXQgW2ViYTQ0OWZhODFmNl0gKFBSICMyOTg3MikgbW9kaWZpZXMgdWRldmFk
bS10cmlnZ2VyCmFuZCBzZC1kZXZpY2UtbW9uaXRvciB0byB1bmNvbmRpdGlvbmFsbHkgaW5jcmVh
c2UgdGhlIHJlY2VpdmUgYnVmZmVyIHNpemUKb24gbmV0bGluayBzb2NrZXRzLiBUaGlzIGhlbHBz
IGF2b2lkIGZhaWx1cmVzIHVuZGVyIGhpZ2ggZXZlbnQgbG9hZHMsCnN1Y2ggYXM6CndhaXQtZm9y
LXVkZXY6IEZhaWxlZCB0byBpbmNyZWFzZSByZWNlaXZlIGJ1ZmZlciBzaXplLCBpZ25vcmluZzog
T3BlcmF0aW9uIG5vdCBwZXJtaXR0ZWQKClRvIGFkZHJlc3M6ICJ3YWl0LWZvci11ZGV2OiBGYWls
ZWQgdG8gaW5jcmVhc2UgcmVjZWl2ZSBidWZmZXIgc2l6ZSwgaWdub3Jpbmc6Ck9wZXJhdGlvbiBu
b3QgcGVybWl0dGVkIiwgd2UgbmVlZCB0byBhbGxvdyB1ZGV2YWRtIHRvIGluY3JlYXNlIHRoZSBi
dWZmZXIuClRoaXMgbWF5IGZpeCB0aGUgaXNzdWUgdGhhdCB1ZGV2YWRtIHRyaWdnZXIgaGFuZ3Mg
d2hpbGUgcHJvY2Vzc2luZyB0aGUgZXZlbnRzClJlZmVyZW5jZXM6Ci0gaHR0cHM6Ly9naXRodWIu
Y29tL3N5c3RlbWQvc3lzdGVtZC9wdWxsLzI5ODcyCgpUbyBzdXBwb3J0IHRoaXMgaW4gU0VMaW51
eCwgQWxsb3cgdWRldmFkbSB0byB1c2UgQ0FQX05FVF9BRE1JTiB0byBleHRlbmQKdGhlIHNvY2tl
dCByZWNlaXZlIGJ1ZmZlciB0byBob2xkIG1vcmUgZXZlbnRzLgoKU2lnbmVkLW9mZi1ieTogQmhh
YnUgQmluZHUgPEJoYWJ1LkJpbmR1QGtwaXQuY29tPgotLS0KIHBvbGljeS9tb2R1bGVzL3N5c3Rl
bS91ZGV2LnRlIHwgMyArKysKIDEgZmlsZSBjaGFuZ2VkLCAzIGluc2VydGlvbnMoKykKCmRpZmYg
LS1naXQgYS9wb2xpY3kvbW9kdWxlcy9zeXN0ZW0vdWRldi50ZSBiL3BvbGljeS9tb2R1bGVzL3N5
c3RlbS91ZGV2LnRlCmluZGV4IGUyNDVhNjZhNC4uODJmZTgzNTRkIDEwMDY0NAotLS0gYS9wb2xp
Y3kvbW9kdWxlcy9zeXN0ZW0vdWRldi50ZQorKysgYi9wb2xpY3kvbW9kdWxlcy9zeXN0ZW0vdWRl
di50ZQpAQCAtNDQ3LDMgKzQ0Nyw2IEBAIHNldXRpbF9yZWFkX2ZpbGVfY29udGV4dHModWRldmFk
bV90KQogc3RvcmFnZV9nZXRhdHRyX2ZpeGVkX2Rpc2tfZGV2KHVkZXZhZG1fdCkKIAogdXNlcmRv
bV91c2VfdXNlcl90ZXJtaW5hbHModWRldmFkbV90KQorCisjIEFsbG93IHVkZXZhZG0gdG8gdXNl
IENBUF9ORVRfQURNSU4gdG8gZXh0ZW5kIHRoZSBzb2NrZXQgcmVjZWl2ZSBidWZmZXIgdG8gaG9s
ZCBtb3JlIGV2ZW50cworYWxsb3cgdWRldmFkbV90IHNlbGY6Y2FwYWJpbGl0eSB7IG5ldF9hZG1p
biB9OwotLSAKMi4zNC4xCgo=

--_004_MA0PR01MB97933ED6DCFEADB1CB62BDB3958FAMA0PR01MB9793INDP_--