f865919872
With systemd, /etc/resolv.conf is a symlink to /run/systemd/resolve/resolv.conf allow domains with access to read network configuration to read this file. Please note, this can't be in optional due to tunable_policy in nis_authenticate interface. type=AVC msg=audit(1523455881.596:214): avc: denied { search } for pid=944 comm="chronyd" name="resolve" dev="tmpfs" ino=14267 scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=dir type=AVC msg=audit(1523455881.596:214): avc: denied { read } for pid=944 comm="chronyd" name="resolv.conf" dev="tmpfs" ino=14277 scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=file type=AVC msg=audit(1523455881.596:214): avc: denied { open } for pid=944 comm="chronyd" path="/run/systemd/resolve/resolv.conf" dev="tmpfs" ino=14277 scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=file type=AVC msg=audit(1523455881.596:215): avc: denied { getattr } for pid=944 comm="chronyd" path="/run/systemd/resolve/resolv.conf" dev="tmpfs" ino=14277 scontext=system_u:system_r:chronyd_t:s0 tcontext=system_u:object_r:systemd_resolved_var_run_t:s0 tclass=file Signed-off-by: Dave Sugar <dsugar@tresys.com> |
||
---|---|---|
.. | ||
application.fc | ||
application.if | ||
application.te | ||
authlogin.fc | ||
authlogin.if | ||
authlogin.te | ||
clock.fc | ||
clock.if | ||
clock.te | ||
fstools.fc | ||
fstools.if | ||
fstools.te | ||
getty.fc | ||
getty.if | ||
getty.te | ||
hostname.fc | ||
hostname.if | ||
hostname.te | ||
hotplug.fc | ||
hotplug.if | ||
hotplug.te | ||
init.fc | ||
init.if | ||
init.te | ||
ipsec.fc | ||
ipsec.if | ||
ipsec.te | ||
iptables.fc | ||
iptables.if | ||
iptables.te | ||
libraries.fc | ||
libraries.if | ||
libraries.te | ||
locallogin.fc | ||
locallogin.if | ||
locallogin.te | ||
logging.fc | ||
logging.if | ||
logging.te | ||
lvm.fc | ||
lvm.if | ||
lvm.te | ||
metadata.xml | ||
miscfiles.fc | ||
miscfiles.if | ||
miscfiles.te | ||
modutils.fc | ||
modutils.if | ||
modutils.te | ||
mount.fc | ||
mount.if | ||
mount.te | ||
netlabel.fc | ||
netlabel.if | ||
netlabel.te | ||
selinuxutil.fc | ||
selinuxutil.if | ||
selinuxutil.te | ||
setrans.fc | ||
setrans.if | ||
setrans.te | ||
sysnetwork.fc | ||
sysnetwork.if | ||
sysnetwork.te | ||
systemd.fc | ||
systemd.if | ||
systemd.te | ||
udev.fc | ||
udev.if | ||
udev.te | ||
unconfined.fc | ||
unconfined.if | ||
unconfined.te | ||
userdomain.fc | ||
userdomain.if | ||
userdomain.te |