Bug 1220372

Summary: [SELinux] setroubleshootd: avc denials crypt_device_t and random_device_t
Product: [openSUSE] openSUSE Tumbleweed Reporter: Cathy Hu <cathy.hu>
Component: SecurityAssignee: Cathy Hu <cathy.hu>
Status: RESOLVED INVALID QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: jsegitz
Version: Current   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Cathy Hu 2024-02-26 16:10:55 UTC
setroubleshootd avc denials in sle micro 6.0

avc: denied { read write } comm="setroubleshootd" scontext=system_u:system_r:setroubleshootd_t:s0 tcontext=system_u:object_r:crypt_device_t:s0 tclass=chr_file permissive=0

avc: denied { read } comm="setroubleshootd" scontext=system_u:system_r:setroubleshootd_t:s0 tcontext=system_u:object_r:random_device_t:s0 tclass=chr_file permissive=0

e.g.
https://openqa.suse.de/tests/13602660/#step/suseconnect_scc/67
https://openqa.suse.de/tests/13602660/#step/host_config/48
Comment 1 Cathy Hu 2024-03-07 14:37:12 UTC
this one vanished with the fix of bsc#1220373, so closing