4067a18530
When an unconfined_t root user runs dmesg, the kernel complains with this message in its logs (when SELinux is in enforcing mode): dmesg (16289): Attempt to access syslog with CAP_SYS_ADMIN but no CAP_SYSLOG (deprecated). audit.log contains following AVC: avc: denied { syslog } for pid=16289 comm="dmesg" capability=34 scontext=unconfined_u:unconfined_r:unconfined_t tcontext=unconfined_u:unconfined_r:unconfined_t tclass=capability2 |
||
---|---|---|
.. | ||
flask | ||
modules | ||
support | ||
constraints | ||
context_defaults | ||
global_booleans | ||
global_tunables | ||
mcs | ||
mls | ||
policy_capabilities | ||
users |