Re: [PATCH v3] selinux: suppress warning flood for retired DCCP netlink messages
Stephen Smalley <[email protected]>
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <CAEjxPJ4-dAdgC9EaNRzm8auqTy=TAnF6Gp-q7JGqZ2VDGkvh3w@mail.gmail.com> |
On Thu, Jul 9, 2026 at 2:31 AM Yafang Shao <[email protected]> wrote: > > When deploying linux-6.18.y stable kernel to production servers, we > observed kernel dmesg being flooded with SELinux warnings when running > `ss -l`: > > SELinux: unrecognized netlink message: protocol=4 nlmsg_type=19 \ > sclass=netlink_tcpdiag_socket pid=188945 comm=ss > > The root cause is that DCCP support was retired in > commit 2a63dd0edf38 ("net: Retire DCCP socket."). Consequently, > DCCPDIAG_GETSOCK was removed from nlmsg_tcpdiag_perms. This causes > nlmsg_perm() to return -EINVAL, triggering the SELinux warning for every > `ss -l` invocation [0]. > > Use pr_warn_once() for the retired DCCPDIAG_GETSOCK to prevent message > flooding. > > Link: https://github.com/iproute2/iproute2/blob/main/misc/ss.c#L3901 [0] > Fixes: 2a63dd0edf38 ("net: Retire DCCP socket.") > Suggested-by: Paul Moore <[email protected]> > Signed-off-by: Yafang Shao <[email protected]> > Cc: Kuniyuki Iwashima <[email protected]> > Cc: Stephen Smalley <[email protected]> Acked-by: Stephen Smalley <[email protected]> > --- > security/selinux/hooks.c | 18 ++++++++++++------ > 1 file changed, 12 insertions(+), 6 deletions(-) > > v2->v3: check also the sclass (sashiko-bot, Stephen) > v1->v2: use pr_warn_once for the removed DCCPDIAG_GETSOCK (Paul) > > diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c > index 1a713d96206f..8a9ec06e40ab 100644 > --- a/security/selinux/hooks.c > +++ b/security/selinux/hooks.c > @@ -94,6 +94,7 @@ > #include <linux/io_uring/cmd.h> > #include <uapi/linux/lsm.h> > #include <linux/memfd.h> > +#include <uapi/linux/inet_diag.h> > > #include "initcalls.h" > #include "avc.h" > @@ -6272,12 +6273,17 @@ static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb) > return rc; > } else if (rc == -EINVAL) { > /* -EINVAL is a missing msg/perm mapping */ > - pr_warn_ratelimited("SELinux: unrecognized netlink" > - " message: protocol=%hu nlmsg_type=%hu sclass=%s" > - " pid=%d comm=%s\n", > - sk->sk_protocol, nlh->nlmsg_type, > - secclass_map[sclass - 1].name, > - task_pid_nr(current), current->comm); > + if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET && > + nlh->nlmsg_type == DCCPDIAG_GETSOCK) > + pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n", > + task_pid_nr(current), current->comm); > + else > + pr_warn_ratelimited("SELinux: unrecognized netlink" > + " message: protocol=%hu nlmsg_type=%hu sclass=%s" > + " pid=%d comm=%s\n", > + sk->sk_protocol, nlh->nlmsg_type, > + secclass_map[sclass - 1].name, > + task_pid_nr(current), current->comm); > if (enforcing_enabled() && > !security_get_allow_unknown()) > return rc; > -- > 2.52.0 >