pidfs
Russell Coker <[email protected]> Sat, 07 Dec 2024 14:22:41 +1100
| Newsgroups | org.kernel.vger.selinux-refpolicy |
|---|---|
| Message-ID | <1985778.PYKUYFuaPT@cupcakke> |
What's this new pidfs that seems to have just become visible in 6.11.10 or
similar recent kernels?
https://lwn.net/Articles/714932/
The above article has some information about a previous iteration of it,
apparently not a separate mountable filesystem but a part of /proc that can be
mounted as part of a container.
I'm seeing the following audit entries about it, what should we do in policy
about this?
type=AVC msg=audit(1733540968.538:31305): avc: denied { getattr } for
pid=1465 comm="systemd" name="/" dev="pidfs" ino=1
scontext=etbe:user_r:user_systemd_t:s0-s0:c0.c1023
tcontext=system_u:object_r:unlabeled_t:s0 tclass=filesystem permissive=0
--
My Main Blog http://etbe.coker.com.au/
My Documents Blog http://doc.coker.com.au/