Re: /run/credentials
Dominick Grift <[email protected]> Fri, 10 Jul 2026 12:04:37 +0200
| Newsgroups | org.kernel.vger.selinux-refpolicy |
|---|---|
| Message-ID | <[email protected]> |
Russell Coker <[email protected]> writes: > Does anyone have any policy for credentials? I do but it did you age as well as it could have. > > Below is what I'm getting on my systems running Debian/Testing, directories > like the following with no files in them. > > # find /run/credentials/ > /run/credentials/ > /run/credentials/[email protected] > /run/credentials/systemd-resolved.service > /run/credentials/systemd-journald.service > # find /run/credentials/ -type f > # > > Currently what is happening is daemons trying to read their own dir and being > denied, here's an example: > > type=AVC msg=audit(1783593117.796:143): avc: denied { open } for pid=1034 > comm="agetty" path="/run/credentials/[email protected]" dev="tmpfs" ino=1 > scontext=system_u:system_r:getty_t:s0 tcontext=system_u:object_r:tmpfs_t:s0 > tclass=dir permissive=1 > > I was thinking of adding a credentials_runtime_t type and labelling everything > under /run/credentials with it, giving daemons read-access to directories and > wait to write real policy until people make daemons actually use it. Did you read this: https://systemd.io/CREDENTIALS/ -- gpg --auto-key-locate clear,nodefault,wkd --locate-external-keys [email protected] Key fingerprint = FCD2 3660 5D6B 9D27 7FC6 E0FF DA7E 521F 10F6 4098 Dominick Grift Mastodon: @[email protected]