Skip to content

Commit 3e391f4

Browse files
committed
Allow gnome-remote-desktop read sssd public files
The commit addresses the following AVC denial: type=AVC msg=audit(1762431526.77:934): avc: denied { read } for pid=62388 comm=52445020736F636B65742074687265 path="/var/lib/sss/pubconf/krb5.include.d" dev="dm-5" ino=537158989 scontext=system_u:system_r:gnome_remote_desktop_t:s0 tcontext=system_u:object_r:sssd_public_t:s0 tclass=dir permissive=1 Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=2413082
1 parent 93dceea commit 3e391f4

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

policy/modules/contrib/gnome_remote_desktop.te

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,10 @@ optional_policy(`
6969
policykit_dbus_chat(gnome_remote_desktop_t)
7070
')
7171

72+
optional_policy(`
73+
sssd_read_public_files(gnome_remote_desktop_t)
74+
')
75+
7276
optional_policy(`
7377
sysnet_read_config(gnome_remote_desktop_t)
7478
')

0 commit comments

Comments
 (0)