selinux-refpolicy/policy
Kenton Groombridge 4e7511f4ac init: allow using system bus anon pidfs
Seen with systemd 255. This initially did not seem to impact anything,
but after a while I found that the kubernetes kubelet agent would not
start without this access.

type=AVC msg=audit(1705092131.239:37): avc:  denied  { use } for  pid=1 comm="systemd" path="anon_inode:[pidfd]" dev="anon_inodefs" ino=10 scontext=system_u:system_r:init_t:s0 tcontext=system_u:system_r:system_dbusd_t:s0 tclass=fd permissive=0

Signed-off-by: Kenton Groombridge <concord@gentoo.org>
2024-02-21 15:30:53 -05:00
..
flask Define user_namespace object class. 2023-03-02 09:00:45 -05:00
modules init: allow using system bus anon pidfs 2024-02-21 15:30:53 -05:00
support patches for nspawn policy (#721) 2023-10-09 09:32:38 -04:00
constraints
context_defaults
global_booleans
global_tunables
mcs
mls
policy_capabilities
users