Bug 1915034

Summary: Add watch permissions to selinux-policy
Product: [Fedora] Fedora Reporter: Zdenek Pytela <zpytela>
Component: selinux-policyAssignee: Zdenek Pytela <zpytela>
Status: CLOSED RAWHIDE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: high    
Version: 34CC: dwalsh, grepl.miroslav, lvrabec, mmalik, omosnace, plautrba, vmojzis, zpytela
Target Milestone: ---Keywords: Triaged
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-02-09 16:29:18 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Zdenek Pytela 2021-01-11 19:44:31 UTC
Add watch permissions to selinux-policy and update policy rules for domains requiring this access.

The permissions list is:
watch watch_mount watch_sb watch_with_perm watch_reads

Comment 1 Milos Malik 2021-01-19 10:27:48 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/170

The PR waits for review.

Comment 2 Ben Cotton 2021-02-09 16:22:42 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 34 development cycle.
Changing version to 34.

Comment 3 Zdenek Pytela 2021-02-15 19:23:09 UTC
Adding the original pull request link for the future reference:
https://github.com/fedora-selinux/selinux-policy/pull/546