lnk_file read permission

Gionatan Danti <[email protected]>
Newsgroups gmane.linux.redhat.fedora.selinux
Message-ID <[email protected]>
Hi all,
using selinux, I saw many times that when relocating service dirs (eg: 
mysql, mongodb, etc) putting a symlink in the original location, the 
affected services fail to start due to missing lnk_file read permission.

As selinux works with target file label and it is path-agnostic (this 
is, indeed, a major selinux feature), while is the lnk_file read often 
not granted by default? Does granting it expose to additional attack 
vectors?

Thanks.

-- 
Danti Gionatan
Supporto Tecnico
Assyoma S.r.l. - www.assyoma.it [1]
email: [email protected] - [email protected]
GPG public key ID: FF5F32A8
_______________________________________________
selinux mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.