Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Access to udev "database" #221

Closed
bigon opened this issue Apr 15, 2020 · 1 comment · Fixed by #331
Closed

Access to udev "database" #221

bigon opened this issue Apr 15, 2020 · 1 comment · Fixed by #331

Comments

@bigon
Copy link
Contributor

bigon commented Apr 15, 2020

Hello,

The udev module still references the udev_tbl_t as being stored in /dev, but these days, it's located in /run. That prevents some applications (like pcscd) to work properly.

Red Hat went the way of removing the udev_tbl_t type completely, see fedora-selinux/selinux-policy@382acd84f3

Would that be the road to go as well?

@pebenito
Copy link
Member

Sounds like it is the right choice.

bigon added a commit to bigon/refpolicy that referenced this issue Apr 17, 2020
This location is gone for quite some times and the udevdb has been moved
to /run/udev.

Drop the udev_tbl_t and deprecate the udev_read_db() function

This inspired from changes in the Red Hat policy

Signed-off-by: Laurent Bigonville <bigon@bigon.be>

Fixes: SELinuxProject#221
bigon added a commit to bigon/refpolicy that referenced this issue Apr 19, 2020
This location is gone for quite some times and the udevdb has been moved
to /run/udev.

Drop the udev_tbl_t and deprecate the udev_read_db() function

This inspired from changes in the Red Hat policy

Signed-off-by: Laurent Bigonville <bigon@bigon.be>

Fixes: SELinuxProject#221
bigon added a commit to bigon/refpolicy that referenced this issue Apr 19, 2020
This location is gone for quite some times and the udevdb has been moved
to /run/udev.

Drop the udev_tbl_t and deprecate the udev_read_db() function

This inspired from changes in the Red Hat policy

Signed-off-by: Laurent Bigonville <bigon@bigon.be>

Fixes: SELinuxProject#221
pebenito added a commit to pebenito/refpolicy that referenced this issue Jan 8, 2021
This usage under /dev/.udev has been unused for a very long time and
replaced by functionality in /run/udev.  Since these have separate types,
take this opportunity to revoke these likely unnecessary rules.

Fixes SELinuxProject#221

Derived from Laurent Bigonville's work in SELinuxProject#230

Signed-off-by: Chris PeBenito <pebenito@ieee.org>
@pebenito pebenito mentioned this issue Jan 8, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants