Re: /run/credentials

Dominick Grift <[email protected]> Fri, 10 Jul 2026 12:04:37 +0200
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
Russell Coker <[email protected]> writes:

> Does anyone have any policy for credentials?  

I do but it did you age as well as it could have.

>
> Below is what I'm getting on my systems running Debian/Testing, directories 
> like the following with no files in them.
>
> # find /run/credentials/
> /run/credentials/
> /run/credentials/[email protected]
> /run/credentials/systemd-resolved.service
> /run/credentials/systemd-journald.service
> # find /run/credentials/ -type f
> # 
>
> Currently what is happening is daemons trying to read their own dir and being 
> denied, here's an example:
>
> type=AVC msg=audit(1783593117.796:143): avc:  denied  { open } for  pid=1034 
> comm="agetty" path="/run/credentials/[email protected]" dev="tmpfs" ino=1 
> scontext=system_u:system_r:getty_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 
> tclass=dir permissive=1
>
> I was thinking of adding a credentials_runtime_t type and labelling everything 
> under /run/credentials with it, giving daemons read-access to directories and 
> wait to write real policy until people make daemons actually use it.

Did you read this:

https://systemd.io/CREDENTIALS/


-- 
gpg --auto-key-locate clear,nodefault,wkd --locate-external-keys [email protected]
Key fingerprint = FCD2 3660 5D6B 9D27 7FC6  E0FF DA7E 521F 10F6 4098
Dominick Grift
Mastodon: @[email protected]