LINUXOR.SK ... open source notes ...

Email - keepalived-local-1.0.te (SELinux module)

category: solutionz · date: 2019-12-31 · updated: 2026-10-02 · author: LALA

Email Solution · Config document · referenced from Virtual machines and OS build

noteThis module is a harvest of an audit log, not a designed policy. Most of its rules are a list of what happened to be running on one server, and three of them allow Keepalived to run systemctl, which nothing in the archived configuration does.

A local SELinux type-enforcement module for Keepalived on the internal pair. Keepalived checks Postfix and Dovecot with killall -0, and the stock policy does not let keepalived_t look at other daemons or send them a signal.

ItemValue
Path on the server/etc/selinux/keepalived-local-1.0.te
Shown hereDC2-A-VCMSX001
Also onDC2-B-VCMSX001, identical
Compiled withcheckmodule -M -m -o keepalived-local-1.0.mod keepalived-local-1.0.te, then semodule_package -o keepalived-local-1.0.pp -m keepalived-local-1.0.mod
Loaded withsemodule -i keepalived-local-1.0.pp
SELinux modeenforcing, targeted policy

The file

c
module keepalived-local-1.0 1.0;

require {
        type auditd_exec_t;
        type gssd_exec_t;
        type udev_exec_t;
        type httpd_exec_t;
        type rhnsd_exec_t;
        type ssh_exec_t;
        type syslogd_exec_t;
        type oddjob_exec_t;
        type policykit_exec_t;
        type dovecot_t;
        type postfix_qmgr_exec_t;
        type ntpd_exec_t;
        type lvm_exec_t;
        type systemd_systemctl_exec_t;
        type su_exec_t;
        type mysqld_exec_t;
        type sudo_exec_t;
        type postfix_master_exec_t;
        type rhsmcertd_exec_t;
        type postfix_pickup_exec_t;
        type gssproxy_exec_t;
        type init_exec_t;
        type crond_exec_t;
        type virt_qemu_ga_exec_t;
        type postfix_master_t;
        type systemd_hostnamed_exec_t;
        type sssd_exec_t;
        type sshd_exec_t;
        type dbusd_exec_t;
        type systemd_unit_file_t;
        type ping_exec_t;
        type getty_exec_t;
        type init_t;
        type systemd_logind_exec_t;
        type dovecot_exec_t;
        type keepalived_t;
        class process signull;
        class unix_stream_socket connectto;
        class service { start status };
        class file { execute execute_no_trans getattr open read };
}

#============= keepalived_t ==============
allow keepalived_t auditd_exec_t:file getattr;
allow keepalived_t crond_exec_t:file getattr;
allow keepalived_t dbusd_exec_t:file getattr;
allow keepalived_t dovecot_exec_t:file getattr;
allow keepalived_t dovecot_t:process signull;
allow keepalived_t getty_exec_t:file getattr;
allow keepalived_t gssd_exec_t:file getattr;
allow keepalived_t gssproxy_exec_t:file getattr;
allow keepalived_t httpd_exec_t:file getattr;
allow keepalived_t init_exec_t:file getattr;
allow keepalived_t init_t:unix_stream_socket connectto;
allow keepalived_t lvm_exec_t:file getattr;
allow keepalived_t mysqld_exec_t:file getattr;
allow keepalived_t ntpd_exec_t:file getattr;
allow keepalived_t oddjob_exec_t:file getattr;
allow keepalived_t ping_exec_t:file getattr;
allow keepalived_t policykit_exec_t:file getattr;
allow keepalived_t postfix_master_exec_t:file getattr;
allow keepalived_t postfix_master_t:process signull;
allow keepalived_t postfix_pickup_exec_t:file getattr;
allow keepalived_t postfix_qmgr_exec_t:file getattr;
allow keepalived_t rhnsd_exec_t:file getattr;
allow keepalived_t rhsmcertd_exec_t:file getattr;
allow keepalived_t ssh_exec_t:file getattr;
allow keepalived_t sshd_exec_t:file getattr;
allow keepalived_t sssd_exec_t:file getattr;
allow keepalived_t su_exec_t:file getattr;
allow keepalived_t sudo_exec_t:file getattr;
allow keepalived_t syslogd_exec_t:file getattr;
allow keepalived_t systemd_hostnamed_exec_t:file getattr;
allow keepalived_t systemd_logind_exec_t:file getattr;
allow keepalived_t systemd_systemctl_exec_t:file { execute execute_no_trans getattr open read };
allow keepalived_t systemd_unit_file_t:service { start status };
allow keepalived_t udev_exec_t:file getattr;
allow keepalived_t virt_qemu_ga_exec_t:file getattr;

Reading the rules

RulesWhat they are for
postfix_master_t:process signull, dovecot_t:process signullThe check itself: killall -0 master and killall -0 dovecot send signal 0 to the process
getattr on thirty *_exec_t fileskillall looks at the executable of every running process to find the name it was given; each daemon on the server produced one denial
systemd_systemctl_exec_t:file { execute execute_no_trans getattr open read }, systemd_unit_file_t:service { start status }, init_t:unix_stream_socket connecttoKeepalived running systemctl to query and start a unit. The archived keepalived.conf has no script that does this, and the install notes do not explain it

The design document names the file /etc/selinux/keepalived-local.te; on the servers and in the install notes it is keepalived-local-1.0.te.

Checked against RHEL 10.2 and Keepalived 2.4.3

As builtToday
Process check with killall -0 in a vrrp_script, which is what made this module necessaryKeepalived has a native vrrp_track_process, built on the kernel's process-events connector, and its manual page carries a section "Rational for not using pgrep/pidof/killall". CentOS Stream 9 and 10, the upstream of RHEL 9 and 10, carry Keepalived 2.2.8
Scripts run without script_user and enable_script_securityscript_user defaults to the user keepalived_script if it exists, otherwise to the user Keepalived runs as; enable_script_security refuses scripts run as root when any part of their path is writable by a non-root user
.te compiled with checkmodule -M -m, packaged with semodule_package, loaded with semodule -iStill works; checkpolicy and policycoreutils are shipped. The Red Hat SELinux guide for RHEL 10 no longer shows checkmodule: it shows audit2allow -M <name> followed by semodule -X 300 -i <name>.pp, and local modules written as .cil files that semodule -i loads directly
A local module with its own rulesRed Hat states that custom modules with own rules are outside the support scope

With the native process tracking there would be no killall, no walk over every process on the server, and most of this module would have no reason to exist. The type names in it were not checked against the current policy.

← solutionz