On boot I am seeing: Sep 25 17:26:38 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:38 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:38 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:39 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:39 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:39 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:42 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:42 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:42 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:44 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:58 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:59 voldemort.scrye.com audit[1221]: AVC avc: denied { read } for pid=1221 comm="systemd-logind" name="OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:59 voldemort.scrye.com audit[1221]: AVC avc: denied { open } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1 Sep 25 17:26:59 voldemort.scrye.com audit[1221]: AVC avc: denied { getattr } for pid=1221 comm="systemd-logind" path="/sys/firmware/efi/efivars/OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c" dev="efivarfs" ino=10917 scontext=system_u:system_r:systemd_logind_t:s0 tcontext=system_u:object_r:efivarfs_t:s0 tclass=file permissive=1
diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index 8209291..92de375 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -106,6 +106,9 @@ files_delete_tmpfs_files(systemd_logind_t) fs_mount_tmpfs(systemd_logind_t) fs_unmount_tmpfs(systemd_logind_t) fs_list_tmpfs(systemd_logind_t) + +fs_read_efivarfs_files(systemd_logind_t) Please update to the latest rawhide. Thank you.