Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 468874 - dhcpc_t policy does not allow IPv6 addresses
Summary: dhcpc_t policy does not allow IPv6 addresses
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: SELinux (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Sven Vermeulen (RETIRED)
URL:
Whiteboard: sec-policy r2
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-07 13:34 UTC by Sven Vermeulen (RETIRED)
Modified: 2013-08-15 07:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sven Vermeulen (RETIRED) gentoo-dev 2013-05-07 13:34:46 UTC
When using dhcpcd to get an IPv6 address based on the Neighbor Discovery Protocol (IPv6 NDP), the request fails with;

"""
ipv6rs: Permission denied
"""

In the audit log, a denial is shown about dhcpc_t wanting to create a rawip_socket (scontext/tcontext both dhcpcd_t).

After allowing this (create_socket_perms), the client succeeds.

Reproducible: Always
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2013-06-23 10:11:23 UTC
Pushed to repo (was sent upstream as well, but no result). Will be in rev2
Comment 2 Sven Vermeulen (RETIRED) gentoo-dev 2013-07-21 16:26:38 UTC
In repo, ~arch (rev 2 of the policies)
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2013-08-15 07:47:29 UTC
r2 is now stable