fedora-selinux / selinux-policy

selinux-policy for Fedora is a large patch off the mainline
GNU General Public License v2.0
156 stars 157 forks source link

Allow sssd create and use io_uring #2095

Closed zpytela closed 2 months ago

zpytela commented 2 months ago

The commit addresses the following AVC denials: avc: denied { create } for pid=879 comm="nsupdate" anonclass=[io_uring] scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:io_uring_t:s0 tclass=anon_inode permissive=1 avc: denied { map } for pid=879 comm="nsupdate" path="anon_inode:[io_uring]" dev="anon_inodefs" ino=11274 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:io_uring_t:s0 tclass=anon_inode permissive=1 avc: denied { read write } for pid=879 comm="nsupdate" path="anon_inode:[io_uring]" dev="anon_inodefs" ino=11274 scontext=system_u:system_r:sssd_t:s0 tcontext=system_u:object_r:io_uring_t:s0 tclass=anon_inode permissive=1

Resolves: rhbz#2276937