[PATCH v3] selinux: suppress warning flood for retired DCCP netlink messages
Yafang Shao <[email protected]>
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <[email protected]> |
When deploying linux-6.18.y stable kernel to production servers, we
observed kernel dmesg being flooded with SELinux warnings when running
`ss -l`:
SELinux: unrecognized netlink message: protocol=4 nlmsg_type=19 \
sclass=netlink_tcpdiag_socket pid=188945 comm=ss
The root cause is that DCCP support was retired in
commit 2a63dd0edf38 ("net: Retire DCCP socket."). Consequently,
DCCPDIAG_GETSOCK was removed from nlmsg_tcpdiag_perms. This causes
nlmsg_perm() to return -EINVAL, triggering the SELinux warning for every
`ss -l` invocation [0].
Use pr_warn_once() for the retired DCCPDIAG_GETSOCK to prevent message
flooding.
Link: https://github.com/iproute2/iproute2/blob/main/misc/ss.c#L3901 [0]
Fixes: 2a63dd0edf38 ("net: Retire DCCP socket.")
Suggested-by: Paul Moore <[email protected]>
Signed-off-by: Yafang Shao <[email protected]>
Cc: Kuniyuki Iwashima <[email protected]>
Cc: Stephen Smalley <[email protected]>
---
security/selinux/hooks.c | 18 ++++++++++++------
1 file changed, 12 insertions(+), 6 deletions(-)
v2->v3: check also the sclass (sashiko-bot, Stephen)
v1->v2: use pr_warn_once for the removed DCCPDIAG_GETSOCK (Paul)
diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c
index 1a713d96206f..8a9ec06e40ab 100644
--- a/security/selinux/hooks.c
+++ b/security/selinux/hooks.c
@@ -94,6 +94,7 @@
#include <linux/io_uring/cmd.h>
#include <uapi/linux/lsm.h>
#include <linux/memfd.h>
+#include <uapi/linux/inet_diag.h>
#include "initcalls.h"
#include "avc.h"
@@ -6272,12 +6273,17 @@ static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb)
return rc;
} else if (rc == -EINVAL) {
/* -EINVAL is a missing msg/perm mapping */
- pr_warn_ratelimited("SELinux: unrecognized netlink"
- " message: protocol=%hu nlmsg_type=%hu sclass=%s"
- " pid=%d comm=%s\n",
- sk->sk_protocol, nlh->nlmsg_type,
- secclass_map[sclass - 1].name,
- task_pid_nr(current), current->comm);
+ if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET &&
+ nlh->nlmsg_type == DCCPDIAG_GETSOCK)
+ pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n",
+ task_pid_nr(current), current->comm);
+ else
+ pr_warn_ratelimited("SELinux: unrecognized netlink"
+ " message: protocol=%hu nlmsg_type=%hu sclass=%s"
+ " pid=%d comm=%s\n",
+ sk->sk_protocol, nlh->nlmsg_type,
+ secclass_map[sclass - 1].name,
+ task_pid_nr(current), current->comm);
if (enforcing_enabled() &&
!security_get_allow_unknown())
return rc;
--
2.52.0