Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Dontaudit systemd-hwdb dac_override capability
When systemd-hwdb creates the /etc/udev/hwdb.bin file, dac_override check appears as a result of calling the linkat() syscall. Despite the AVC, the syscall succeeds and the file is created successfully. This seems to be caused by kernel checks order which would use improving, the proper change in kernel may not be easily achieved though. This commit dontaudits the dac_override capability. Additionally, a simple workaround is available for environments where it can be used: sysctl -w fs.protected_hardlinks=0 Related: rhbz#2240221
- Loading branch information