[gentoo-hardened] SELinux: Granting kernel_t (kdevtmpfs) manage rights on /dev/*

2015-03-04 Thread Sven Vermeulen
Hi all I have a situation that I'd like to hear your opinion on. In bug #535992 a what seems like simple problem is asking for quite some work. It covers a currently cosmetic denial (i.e. SELinux is preventing something but that does not seem to have any noticeable impact on the system) regarding

Re: [gentoo-hardened] SELinux: Granting kernel_t (kdevtmpfs) manage rights on /dev/*

2015-03-04 Thread Luis Ressel
On Wed, 4 Mar 2015 20:21:08 + Sven Vermeulen wrote: > 1. I can temporarily ignore the issue, perhaps hiding the cosmetic > denial behind dontaudit statements > 2. I can restrictively add to kernel_t those rules that do not > trigger the neverallow rules and ignore/dontaudit the rest > 3. I ca

Re: [gentoo-hardened] SELinux: Granting kernel_t (kdevtmpfs) manage rights on /dev/*

2015-03-04 Thread Jason Zaman
On Wed, Mar 04, 2015 at 11:04:34PM +0100, Luis Ressel wrote: > On Wed, 4 Mar 2015 20:21:08 + > Sven Vermeulen wrote: > > > 1. I can temporarily ignore the issue, perhaps hiding the cosmetic > > denial behind dontaudit statements > > 2. I can restrictively add to kernel_t those rules that do n