lnk_file read permission
Gionatan Danti <[email protected]>
| Newsgroups | gmane.linux.redhat.fedora.selinux |
|---|---|
| Message-ID | <[email protected]> |
Hi all, using selinux, I saw many times that when relocating service dirs (eg: mysql, mongodb, etc) putting a symlink in the original location, the affected services fail to start due to missing lnk_file read permission. As selinux works with target file label and it is path-agnostic (this is, indeed, a major selinux feature), while is the lnk_file read often not granted by default? Does granting it expose to additional attack vectors? Thanks. -- Danti Gionatan Supporto Tecnico Assyoma S.r.l. - www.assyoma.it [1] email: [email protected] - [email protected] GPG public key ID: FF5F32A8 _______________________________________________ selinux mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected]