fedora-selinux / selinux-policy

selinux-policy for Fedora is a large patch off the mainline
GNU General Public License v2.0
156 stars 157 forks source link

Modify sudo_role_template() to allow getpgid #2056

Closed zpytela closed 4 months ago

zpytela commented 4 months ago

The commit addresses the following AVC denial: type=PROCTITLE msg=audit(03/04/2024 14:15:38.342:337) : proctitle=sudo -i type=SYSCALL msg=audit(03/04/2024 14:15:38.342:337) : arch=x86_64 syscall=getpgid success=no exit=EACCES(Permission denied) a0=0x1062 a1=0x31e a2=0x0 a3=0x8 items=0 ppid=3187 pid=4256 auid=staff uid=staff gid=root euid=root suid=root fsuid=root egid=root sgid=root fsgid=root tty=(none) ses=7 comm=sudo exe=/usr/bin/sudo subj=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 key=(null) type=AVC msg=audit(03/04/2024 14:15:38.342:337) : avc: denied { getpgid } for pid=4256 comm=sudo scontext=staff_u:staff_r:staff_sudo_t:s0-s0:c0.c1023 tcontext=staff_u:staff_r:staff_t:s0-s0:c0.c1023 tclass=process permissive=0