Hide Forgot
Define the nnp_nosuid_transition policy capability used to enable SELinux domain transitions under NNP or nosuid if the nnp_transition permission or nosuid_transition permission is allowed between the old and new contexts. When this capability is not enabled, such transitions remain limited to bounded transitions as they were prior to the introduction of this capability. This feature allows us to create SELinux security policy for systemd services with systemd security feature called: NoNewPrivileges. Affected RHEL components: kernel, libsepol, selinux-policy
Following commits needs to be backported from Fedora Rawhide: commit aba089a03c5bc225b4643142dbeca0fc4522c685 Author: Chris PeBenito <pebenito> Date: Sat Aug 5 12:22:05 2017 -0400 init: Add NoNewPerms support for systemd. commit ba9f3ac2bfe2e131a5bd7e8a75c0e70386cc5d43 Author: Chris PeBenito <pebenito> Date: Sat Aug 5 12:13:21 2017 -0400 Add nnp_nosuid_transition policycap and related class/perm definitions.
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2018:0763