selinux-refpolicy/policy
Yi Zhao 1afa56d20b selinuxutil: allow setfiles_t to read kernel sysctl
Fixes:
avc: denied { read } for pid=171 comm="restorecon" name="cap_last_cap"
dev="proc" ino=1241
scontext=system_u:system_r:setfiles_t:s0-s15:c0.c1023
tcontext=system_u:object_r:sysctl_kernel_t:s0 tclass=file permissive=0

avc: denied { open } for pid=171 comm="restorecon"
path="/proc/sys/kernel/cap_last_cap" dev="proc" ino=1241
scontext=system_u:system_r:setfiles_t:s0-s15:c0.c1023
tcontext=system_u:object_r:sysctl_kernel_t:s0 tclass=file permissive=0

avc: denied { getattr } for pid=171 comm="restorecon" name="/"
dev="proc" ino=1 scontext=system_u:system_r:setfiles_t:s0-s15:c0.c1023
tcontext=system_u:object_r:proc_t:s0 tclass=filesystem permissive=0

Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
2021-10-27 11:20:11 +08:00
..
flask
modules selinuxutil: allow setfiles_t to read kernel sysctl 2021-10-27 11:20:11 +08:00
support file_patterns.spt: Add a mmap_manage_files_pattern(). 2021-01-28 10:51:39 -05:00
constraints
context_defaults
global_booleans
global_tunables
mcs
mls
policy_capabilities
users