selinux: suppress warning flood for retired DCCP netlink messages

When deploying linux-6.18.y stable kernel to production servers, we
observed kernel dmesg being flooded with SELinux warnings when running
`ss -l`:

  SELinux: unrecognized netlink message: protocol=4 nlmsg_type=19 \
    sclass=netlink_tcpdiag_socket pid=188945 comm=ss

The root cause is that DCCP support was retired in
commit 2a63dd0edf ("net: Retire DCCP socket."). Consequently,
DCCPDIAG_GETSOCK was removed from nlmsg_tcpdiag_perms. This causes
nlmsg_perm() to return -EINVAL, triggering the SELinux warning for every
`ss -l` invocation [0].

Use pr_warn_once() for the retired DCCPDIAG_GETSOCK to prevent message
flooding.

Link: https://github.com/iproute2/iproute2/blob/main/misc/ss.c#L3901 [0]
Fixes: 2a63dd0edf ("net: Retire DCCP socket.")
Suggested-by: Paul Moore <paul@paul-moore.com>
Signed-off-by: Yafang Shao <laoar.shao@gmail.com>
Cc: Kuniyuki Iwashima <kuniyu@google.com>
Cc: Stephen Smalley <stephen.smalley.work@gmail.com>
Acked-by: Stephen Smalley <stephen.smalley.work@gmail.com>
Signed-off-by: Paul Moore <paul@paul-moore.com>
This commit is contained in:
Yafang Shao 2026-07-09 14:31:28 +08:00 committed by Paul Moore
parent ef0740b4b7
commit e7a614c008

View File

@ -94,6 +94,7 @@
#include <linux/io_uring/cmd.h>
#include <uapi/linux/lsm.h>
#include <linux/memfd.h>
#include <uapi/linux/inet_diag.h>
#include "initcalls.h"
#include "avc.h"
@ -6272,12 +6273,17 @@ static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb)
return rc;
} else if (rc == -EINVAL) {
/* -EINVAL is a missing msg/perm mapping */
pr_warn_ratelimited("SELinux: unrecognized netlink"
" message: protocol=%hu nlmsg_type=%hu sclass=%s"
" pid=%d comm=%s\n",
sk->sk_protocol, nlh->nlmsg_type,
secclass_map[sclass - 1].name,
task_pid_nr(current), current->comm);
if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET &&
nlh->nlmsg_type == DCCPDIAG_GETSOCK)
pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n",
task_pid_nr(current), current->comm);
else
pr_warn_ratelimited("SELinux: unrecognized netlink"
" message: protocol=%hu nlmsg_type=%hu sclass=%s"
" pid=%d comm=%s\n",
sk->sk_protocol, nlh->nlmsg_type,
secclass_map[sclass - 1].name,
task_pid_nr(current), current->comm);
if (enforcing_enabled() &&
!security_get_allow_unknown())
return rc;