selinux-refpolicy/policy/modules/kernel
David Sugar e7b4159ec5 Denial relabeling /run/systemd/private
I am seeing the following denial (in dmesg) during system startup:
[    4.623332] type=1400 audit(1507767947.042:3): avc:  denied  { relabelto } for  pid=1 comm="systemd" name="private" dev="tmpfs" ino=5865 scontext=system_u:system_r:init_t:s0 tcontext=system_u:object_r:init_var_run_t:s0 tclass=sock_file

It appears that systemd is attempting to relablel the socket file /run/systemd/private to init_var_run_t but doesn't have permission.

Updated to create new interface for relabeling of sock_files rather than adding to existing interface

Signed-off-by: Dave Sugar <dsugar@tresys.com>
2017-10-12 18:00:12 -04:00
..
corecommands.fc label /etc/mcelog/mcelog.setup correctly (for RHEL) 2017-09-23 14:30:35 -04:00
corecommands.if Remove deprecated interfaces older than one year old. 2017-08-06 17:03:17 -04:00
corecommands.te corecommands: Module version bump. 2017-09-23 14:36:56 -04:00
corenetwork.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
corenetwork.if.in Separate read and write interface for tun_tap_device_t 2017-09-06 10:59:34 -04:00
corenetwork.if.m4 refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
corenetwork.te.in Remove complement and wildcard in allow rules. 2017-08-13 16:21:44 -04:00
corenetwork.te.m4 refpolicy: Infiniband pkeys and endports 2017-05-24 19:23:18 -04:00
devices.fc kernel/xen: Update for Xen 4.6 2017-10-09 13:57:47 -04:00
devices.if kernel/xen: Add map permission to the dev_rw_xen 2017-10-09 13:57:47 -04:00
devices.te devices: Module version bump. 2017-10-09 14:51:56 -04:00
domain.fc
domain.if remove trailing whitespaces 2016-12-06 13:45:13 +01:00
domain.te Remove complement and wildcard in allow rules. 2017-08-13 16:21:44 -04:00
files.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
files.if Denial relabeling /run/systemd/private 2017-10-12 18:00:12 -04:00
files.te Module version bumps. 2017-09-13 18:58:07 -04:00
filesystem.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
filesystem.if init: allow systemd to relabel /dev and /run 2017-09-11 20:03:31 -04:00
filesystem.te Several module version bumps. 2017-09-11 20:34:13 -04:00
kernel.fc Add fc for /sys/kernel/debug as debugfs_t 2015-05-06 09:49:40 -04:00
kernel.if Remove deprecated interfaces older than one year old. 2017-08-06 17:03:17 -04:00
kernel.te Remove complement and wildcard in allow rules. 2017-08-13 16:21:44 -04:00
mcs.fc
mcs.if remove trailing whitespaces 2016-12-06 13:45:13 +01:00
mcs.te Bump module versions for release. 2013-04-24 16:14:52 -04:00
metadata.xml
mls.fc
mls.if Remove deprecated interfaces older than one year old. 2017-08-06 17:03:17 -04:00
mls.te remove trailing whitespaces 2016-12-06 13:45:13 +01:00
selinux.fc
selinux.if Remove deprecated interfaces older than one year old. 2017-08-06 17:03:17 -04:00
selinux.te Remove complement and wildcard in allow rules. 2017-08-13 16:21:44 -04:00
storage.fc Create / to /usr equivalence for bin, sbin, and lib, from Russell Coker. 2017-02-04 15:19:35 -05:00
storage.if Fix interface descriptions when duplicate ones are found 2016-01-19 00:17:34 +01:00
storage.te Remove complement and wildcard in allow rules. 2017-08-13 16:21:44 -04:00
terminal.fc Misc fc changes from Russell Coker. 2017-04-06 17:00:28 -04:00
terminal.if terminal: Rename term_create_devpts. 2017-09-11 20:03:58 -04:00
terminal.te Several module version bumps. 2017-09-11 20:34:13 -04:00
ubac.fc
ubac.if
ubac.te