Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Allow udev_t to search all directories with a filesystem type #1887

Merged
merged 1 commit into from
Oct 4, 2023

Conversation

naokitnk
Copy link
Contributor

@naokitnk naokitnk commented Oct 3, 2023

Need to allow udev_t to search all directories with a filesystem type as the domain is not unconfined when mls is used.

FYI, below are the denials this commit addresses.

type=AVC msg=audit(1590664127.231:15): avc: denied { search } for pid=733 comm="systemd-udevd" name="events" dev="tracefs" ino=1069 scontext=system_u:system_r:udev_t:s0-s15:c0.c1023 tcontext=system_u:object_r:tracefs_t:s0 tclass=dir permissive=0
type=AVC msg=audit(1594228982.636:14): avc: denied { search } for pid=609 comm="systemd-udevd" name="/" dev="efivarfs" ino=128 scontext=system_u:system_r:udev_t:s0-s15:c0.c1023 tcontext=system_u:object_r:efivarfs_t:s0 tclass=dir permissive=0

Need to allow udev_t to search all directories with a filesystem type
as the domain is not unconfined when mls is used.

Signed-off-by: Naoki Tanaka <[email protected]>
@zpytela
Copy link
Contributor

zpytela commented Oct 4, 2023

Merging, thank you.

@zpytela zpytela merged commit c412df7 into fedora-selinux:rawhide Oct 4, 2023
7 checks passed
@naokitnk naokitnk deleted the udev branch October 4, 2023 17:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants