Re: fs_rw_tmpfs_files(fwupd_t)

Russell Coker <[email protected]> Sat, 13 Jun 2026 12:53:53 +1000
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <2386758.tgW7RDIVbh@xev>
On Saturday, 13 June 2026 01:15:33 AEST Sugar, David wrote:
> The file in this case is a memfd file (created with memfd_create).  You CAN
> transition this from tmpfs_t to a private type (i.e. fwupd_tmpfs_t).  I
> just dealt with something like this for fapolicyd:
> https://github.com/SELinuxProject/refpolicy/pull/1141  Though I never saw
> denials for the create, the transition will work.

Thanks for the information.

This seems like a kernel bug.  The domains in question aren't permitted to 
create tmpfs_t objects but the domains in question can create them anyway.

-- 
My Main Blog         http://etbe.coker.com.au/
My Documents Blog    http://doc.coker.com.au/