selinux-refpolicy/policy/modules/system
Sugar, David a9ae616800 resolve syslog imuxsock denial
I'm seeing the following error while starting rsyslog:
Nov 17 02:01:38 localhost rsyslogd: cannot create '/run/systemd/journal/syslog': Permission denied [v8.24.0-41.el7_7.2]
Nov 17 02:01:38 localhost rsyslogd: imuxsock does not run because we could not aquire any socket  [v8.24.0-41.el7_7.2]
Nov 17 02:01:38 localhost rsyslogd: activation of module imuxsock failed [v8.24.0-41.el7_7.2]

With the following denials:
type=AVC msg=audit(1573958708.773:1896): avc:  denied  { create } for  pid=2347 comm="rsyslogd" name="syslog" scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:syslogd_runtime_t:s0 tclass=sock_file permissive=1
type=AVC msg=audit(1573958708.773:1897): avc:  denied  { setattr } for  pid=2347 comm="rsyslogd" name="syslog" dev="tmpfs" ino=19368 scontext=system_u:system_r:syslogd_t:s0 tcontext=system_u:object_r:syslogd_runtime_t:s0 tclass=sock_file permissive=1

Signed-off-by: Dave Sugar <dsugar@tresys.com>
2019-11-23 10:24:13 -05:00
..
application.fc
application.if
application.te
authlogin.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
authlogin.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
authlogin.te various: Module version bump. 2019-09-30 20:39:31 -04:00
clock.fc
clock.if
clock.te
daemontools.fc Move all files out of the old contrib directory. 2018-06-23 10:38:58 -04:00
daemontools.if Move all files out of the old contrib directory. 2018-06-23 10:38:58 -04:00
daemontools.te Move all files out of the old contrib directory. 2018-06-23 10:38:58 -04:00
fstools.fc fstools: label e2mmpstatus as fsadm_exec_t 2018-08-04 08:50:06 -04:00
fstools.if dphysswapfile: add interfaces and sysadm access 2017-09-14 17:19:55 -04:00
fstools.te Bump module versions for release. 2019-02-01 15:03:42 -05:00
getty.fc
getty.if
getty.te
hostname.fc
hostname.if
hostname.te Bump module versions for release. 2018-01-14 14:08:09 -05:00
hotplug.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
hotplug.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
hotplug.te various: Module version bump. 2019-09-30 20:39:31 -04:00
init.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
init.if init: Whitespace change. 2019-10-31 03:33:14 -04:00
init.te init: Module version bump. 2019-10-31 04:12:24 -04:00
ipsec.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
ipsec.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
ipsec.te various: Module version bump. 2019-09-30 20:39:31 -04:00
iptables.fc iptables: fcontexts for 1.8.0 2018-07-10 17:25:11 -04:00
iptables.if Add interface to start/stop iptables service 2019-01-12 14:32:00 -05:00
iptables.te Bump module versions for release. 2019-02-01 15:03:42 -05:00
iscsi.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
iscsi.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
iscsi.te various: Module version bump. 2019-09-30 20:39:31 -04:00
libraries.fc libraries: fix some misspellings in patterns 2019-09-01 15:47:57 +02:00
libraries.if Add new mmap permission set and pattern support macros. 2017-12-13 18:58:34 -05:00
libraries.te various: Module version bump. 2019-09-03 19:47:12 -04:00
locallogin.fc
locallogin.if
locallogin.te various: Module version bump. 2019-09-07 16:58:51 -04:00
logging.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
logging.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
logging.te resolve syslog imuxsock denial 2019-11-23 10:24:13 -05:00
lvm.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
lvm.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
lvm.te various: Module version bump. 2019-09-30 20:39:31 -04:00
metadata.xml
miscfiles.fc Remove unescaped single dot from the policy 2019-08-27 23:38:09 +02:00
miscfiles.if New interface to dontaudit access to cert_t 2019-02-20 19:28:45 -08:00
miscfiles.te Various: Module version bump. 2019-08-31 06:55:57 -04:00
modutils.fc Remove unescaped single dot from the policy 2019-08-27 23:38:09 +02:00
modutils.if modutils: libkmod mmap()s modules.dep and *.ko's 2017-09-11 20:31:23 -04:00
modutils.te various: Module version bump. 2019-09-30 20:39:31 -04:00
mount.fc
mount.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
mount.te various: Module version bump. 2019-09-30 20:39:31 -04:00
netlabel.fc
netlabel.if
netlabel.te
pcmcia.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
pcmcia.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
pcmcia.te various: Module version bump. 2019-09-30 20:39:31 -04:00
raid.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
raid.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
raid.te various: Module version bump. 2019-09-30 20:39:31 -04:00
selinuxutil.fc
selinuxutil.if selinuxutil: Add map permissions neccessary for semanage 2017-09-11 20:31:23 -04:00
selinuxutil.te portage, selinuxutil: Module version bump. 2019-09-18 19:40:17 -04:00
setrans.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
setrans.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
setrans.te various: Module version bump. 2019-09-30 20:39:31 -04:00
sysnetwork.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
sysnetwork.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
sysnetwork.te various: Module version bump. 2019-09-30 20:39:31 -04:00
systemd.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
systemd.if Merge pull request #112 from fishilico/systemd-sd-executor-use 2019-09-30 20:43:01 -04:00
systemd.te gpg, systemd: Module version bump. 2019-10-03 19:05:05 -04:00
udev.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
udev.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
udev.te various: Module version bump. 2019-09-30 20:39:31 -04:00
unconfined.fc
unconfined.if unconfined: Add namespaced capabilities. 2019-11-15 11:13:58 -05:00
unconfined.te various: Module version bump. 2019-11-23 09:54:36 -05:00
userdomain.fc Move use of user_devpts_t from terminal.fc to userdomain.fc 2018-04-12 18:44:50 -04:00
userdomain.if systemd: Add initial policy for systemd --user. 2019-04-25 11:18:58 -04:00
userdomain.te various: Module version bump. 2019-09-30 20:39:31 -04:00
xdg.fc freedesktop location support 2018-06-10 13:23:01 -04:00
xdg.if xdg: Introduce xdg_search_cache_dirs 2018-06-24 19:11:14 -04:00
xdg.te Bump module versions for release. 2018-07-01 11:02:33 -04:00
xen.fc Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
xen.if Rename *_var_run_t types to *_runtime_t. 2019-09-30 20:02:43 -04:00
xen.te various: Module version bump. 2019-09-30 20:39:31 -04:00