From e7a614c008efb2f4a5db980be3a4b13b6a170a50 Mon Sep 17 00:00:00 2001 From: Yafang Shao Date: Thu, 9 Jul 2026 14:31:28 +0800 Subject: [PATCH] selinux: suppress warning flood for retired DCCP netlink messages When deploying linux-6.18.y stable kernel to production servers, we observed kernel dmesg being flooded with SELinux warnings when running `ss -l`: SELinux: unrecognized netlink message: protocol=4 nlmsg_type=19 \ sclass=netlink_tcpdiag_socket pid=188945 comm=ss The root cause is that DCCP support was retired in commit 2a63dd0edf38 ("net: Retire DCCP socket."). Consequently, DCCPDIAG_GETSOCK was removed from nlmsg_tcpdiag_perms. This causes nlmsg_perm() to return -EINVAL, triggering the SELinux warning for every `ss -l` invocation [0]. Use pr_warn_once() for the retired DCCPDIAG_GETSOCK to prevent message flooding. Link: https://github.com/iproute2/iproute2/blob/main/misc/ss.c#L3901 [0] Fixes: 2a63dd0edf38 ("net: Retire DCCP socket.") Suggested-by: Paul Moore Signed-off-by: Yafang Shao Cc: Kuniyuki Iwashima Cc: Stephen Smalley Acked-by: Stephen Smalley Signed-off-by: Paul Moore --- security/selinux/hooks.c | 18 ++++++++++++------ 1 file changed, 12 insertions(+), 6 deletions(-) diff --git a/security/selinux/hooks.c b/security/selinux/hooks.c index d1f089917a82..f4a4edbff2bd 100644 --- a/security/selinux/hooks.c +++ b/security/selinux/hooks.c @@ -94,6 +94,7 @@ #include #include #include +#include #include "initcalls.h" #include "avc.h" @@ -6272,12 +6273,17 @@ static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb) return rc; } else if (rc == -EINVAL) { /* -EINVAL is a missing msg/perm mapping */ - pr_warn_ratelimited("SELinux: unrecognized netlink" - " message: protocol=%hu nlmsg_type=%hu sclass=%s" - " pid=%d comm=%s\n", - sk->sk_protocol, nlh->nlmsg_type, - secclass_map[sclass - 1].name, - task_pid_nr(current), current->comm); + if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET && + nlh->nlmsg_type == DCCPDIAG_GETSOCK) + pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n", + task_pid_nr(current), current->comm); + else + pr_warn_ratelimited("SELinux: unrecognized netlink" + " message: protocol=%hu nlmsg_type=%hu sclass=%s" + " pid=%d comm=%s\n", + sk->sk_protocol, nlh->nlmsg_type, + secclass_map[sclass - 1].name, + task_pid_nr(current), current->comm); if (enforcing_enabled() && !security_get_allow_unknown()) return rc;