Re: binding and listening to port work with SELinux, but the process is unable receive data from clients

Lukas Vrabec <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Organization Red Hat, Inc.
Message-ID <[email protected]>
Hi Stephen,

The rule is there for almost 9 years.

https://github.com/fedora-selinux/selinux-policy/commit/54f9ea9e7ccf243b0fbdbeefffb017d95f647cd2

I have no problem to remove it.

Lukas.

On 3/20/19 4:10 PM, Stephen Smalley wrote:
> On 3/20/19 10:56 AM, SZIGETVÁRI János wrote:
>> Hi Stephen,
>>
>> I have to admit, I forgot to mention, that I was creating the policy
>> on RHEL 7.5, not Fedora.
> 
> Nonetheless, the same appears to be true on Fedora.  dontaudit rules for
> all domains obviously make it harder to debug and develop policies for
> new domains.  They should be kept to a minimum.
> 
> I suspect these rules were to silence "noisy" denials when sockets are
> created without SOCK_CLOEXEC and then the process execs into a different
> domain.  But a) in some of those cases, we probably do need/want to
> allow inheritance, so we need to see those denials, and b) we shouldn't
> silence the self case.  Unfortunately we don't have a way to write rules
> that exclude self currently.
> 
>>
>> Sorry about that!
>> János
>>
>> Stephen Smalley <[email protected] <mailto:[email protected]>> ezt
>> írta (időpont: 2019. márc. 20., Sze, 15:45):
>>
>>
>>     Obvious question is why are these being dontaudit'd by Fedora policy.
>>
> _______________________________________________
> selinux mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
> Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
> List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
> List Archives:
> https://lists.fedoraproject.org/archives/list/[email protected]
> 


-- 
Lukas Vrabec
Senior Software Engineer, Security Technologies
Red Hat, Inc.

_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEE3wrP3ArXoyYgAS7LRyAaxC8pzgYFAlySr98ACgkQRyAaxC8p
zgaFzQgApNd4upJr3IdRHiKb0KnR8DUrWSoxRTBnLgivdSLKUsfLPNZns0+KWUzL
5GSzPfXp7WjPil2a3oWP5FtMpVYGooYvPuAba97EOBheL2pTrebn3ccqK65+Pqwe
UiFv9HbIGABrG01Op/1Jewzhn4kZ0lBZoqtX1MiZj+bymTcrcAIiQDXdRMN2dNMl
a8cq9SfHh7FwJuxRkjAeqp+9FArJLO2ZUHuiyfQnnhWOPeRwdoNn+Aq6A+DFc09a
xvVoQtynb+LDZb+KsY6YYwqZUyyJVf8lXshiD+l+KGYPmd759AazKytBu7j5PWEL
dMQaLuZJnXf8xZVnBvPxr7+Ks9pZhg==
=CNCC
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.