Skip to content

Commit

Permalink
Allow virtqemud_t relabel virtqemud_var_run_t sock_files
Browse files Browse the repository at this point in the history
The commit addresses the following AVC denial:
type=PROCTITLE msg=audit(05/31/2024 05:27:41.876:878) : proctitle=/usr/sbin/virtqemud --timeout 120
type=AVC msg=audit(05/31/2024 05:27:41.876:878) : avc:  denied  { relabelfrom } for  pid=9185 comm=rpc-virtqemud name=4-rhel-swtpm.sock dev="tmpfs" ino=2796 scontext=system_u:system_r:virtqemud_t:s0 tcontext=system_u:object_r:virt_var_run_t:s0 tclass=sock_file permissive=1
type=SYSCALL msg=audit(05/31/2024 05:27:41.876:878) : arch=x86_64 syscall=setxattr success=yes exit=0 a0=0x7f4eb4059030 a1=0x7f4edaf19197 a2=0x7f4eb4058be0 a3=0x2d items=0 ppid=8217 pid=9185 auid=unset uid=root gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=unset comm=rpc-virtqemud exe=/usr/sbin/virtqemud subj=system_u:system_r:virtqemud_t:s0 key=(null)

Resolves: RHEL-39668
  • Loading branch information
zpytela committed Dec 10, 2024
1 parent 727bbef commit 75ecdee
Showing 1 changed file with 2 additions and 0 deletions.
2 changes: 2 additions & 0 deletions policy/modules/contrib/virt.te
Original file line number Diff line number Diff line change
Expand Up @@ -2144,6 +2144,8 @@ manage_files_pattern(virtqemud_t, virtqemud_lock_t, virtqemud_lock_t)
files_lock_filetrans(virtqemud_t, virtqemud_lock_t, file)

allow virtqemud_t virtqemud_var_run_t:dir relabelfrom;
allow virtqemud_t virtqemud_var_run_t:sock_file relabelfrom;

manage_dirs_pattern(virtqemud_t, virt_var_run_t, virt_var_run_t)
manage_dirs_pattern(virtqemud_t, virtqemud_var_run_t, virtqemud_var_run_t)
manage_files_pattern(virtqemud_t, virtqemud_var_run_t, virtqemud_var_run_t)
Expand Down

0 comments on commit 75ecdee

Please sign in to comment.