Re: [PATCH] bluetooth: allow bluetooth_helper_t net_admin capability

"Christopher J. PeBenito" <[email protected]> Thu, 7 May 2026 15:21:22 -0400
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
On 5/7/26 1:33 AM, Yepuri Siddu wrote:
> There is no functional failure, because of avc denial we are fixing.

I'm trying to understand how this capability is used. When the access 
was denied, what happened?


> On 5/1/2026 8:30 PM, Christopher J. PeBenito wrote:
>> On 4/30/26 5:37 AM, Yepuri Siddu wrote:
>>> Allow bluetooth_helper_t to use the net_admin capability.
>>>
>>> This fixes the following AVC denial:
>>>
>>> avc:  denied  { net_admin } for  capability=12
>>> scontext=system_u:system_r:bluetooth_helper_t:s0
>>> tcontext=system_u:system_r:bluetooth_helper_t:s0
>>> tclass=capability permissive=0
>>>
>>> Add net_admin to the existing self:capability rule for
>>> bluetooth_helper_t.
>>>
>>> Signed-off-by: Yepuri Siddu <[email protected]>
>>> ---
>>>   policy/modules/services/bluetooth.te | 2 +-
>>>   1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/policy/modules/services/bluetooth.te b/policy/modules/ 
>>> services/bluetooth.te
>>> index ceb42d147..dbd3519d4 100644
>>> --- a/policy/modules/services/bluetooth.te
>>> +++ b/policy/modules/services/bluetooth.te
>>> @@ -178,7 +178,7 @@ optional_policy(`
>>>   # Helper local policy
>>>   #
>>> -allow bluetooth_helper_t self:capability sys_nice;
>>> +allow bluetooth_helper_t self:capability { sys_nice net_admin };
>>>   allow bluetooth_helper_t self:process getsched;
>>>   allow bluetooth_helper_t self:fifo_file rw_fifo_file_perms;
>>>   allow bluetooth_helper_t self:shm create_shm_perms;
>>>
>> What functional failure do you see when this is denied? Do you know 
>> how it is using this capability?
>>
>>
>

-- 
Chris PeBenito