selinux-refpolicy/policy
Nicolas Iooss 4bf3dfaeb2 Allow kdevtmpfs to unlink fixed disk devices
When a device gets removed, for example with "cryptsetup close",
kdevtmpfs (a kernel thread) removes its entry from devtmpfs filesystem:

    avc:  denied  { unlink } for  pid=48 comm="kdevtmpfs"
    name="dm-4" dev="devtmpfs" ino=144111
    scontext=system_u:system_r:kernel_t
    tcontext=system_u:object_r:fixed_disk_device_t tclass=blk_file

Allow this access on systems using systemd.
2016-03-19 11:12:28 +01:00
..
flask Add systemd access vectors. 2015-10-20 15:01:27 -04:00
modules Allow kdevtmpfs to unlink fixed disk devices 2016-03-19 11:12:28 +01:00
support Update netlink socket classes. 2015-05-22 08:29:03 -04:00
constraints Update netlink socket classes. 2015-05-22 08:29:03 -04:00
context_defaults Fix error in default_user example. 2014-04-28 10:19:22 -04:00
global_booleans
global_tunables
mcs
mls Add mls support for some db classes 2016-01-28 15:34:03 -05:00
policy_capabilities Add always_check_network policy capability. 2015-01-27 17:25:36 -05:00
users