Bug 1915034 - Add watch permissions to selinux-policy
Summary: Add watch permissions to selinux-policy
Keywords:
Status: CLOSED RAWHIDE
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 34
Hardware: Unspecified
OS: Unspecified
high
medium
Target Milestone: ---
Assignee: Zdenek Pytela
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-01-11 19:44 UTC by Zdenek Pytela
Modified: 2021-02-15 19:23 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-02-09 16:29:18 UTC
Type: Bug


Attachments (Terms of Use)

Description Zdenek Pytela 2021-01-11 19:44:31 UTC
Add watch permissions to selinux-policy and update policy rules for domains requiring this access.

The permissions list is:
watch watch_mount watch_sb watch_with_perm watch_reads

Comment 1 Milos Malik 2021-01-19 10:27:48 UTC
Test coverage for this bug exists in a form of PR:
 * https://src.fedoraproject.org/tests/selinux/pull-request/170

The PR waits for review.

Comment 2 Ben Cotton 2021-02-09 16:22:42 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 34 development cycle.
Changing version to 34.

Comment 3 Zdenek Pytela 2021-02-15 19:23:09 UTC
Adding the original pull request link for the future reference:
https://github.com/fedora-selinux/selinux-policy/pull/546


Note You need to log in before you can comment on or make changes to this bug.