Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Allow winbind-rpcd use its private tmp files
This permission is required for working with temporary printing files created in the /tmp or /var/tmp directories. The commit addresses the following AVC denial: type=PROCTITLE msg=audit(07/26/2023 07:22:13.392:2480) : proctitle=/bin/bash /usr/local/bin/Pdfprint.sh -s /var/tmp/smbprn.uY9Kob -d /home/smbuser -o smbuser -m 600 -l /var/log/samba/lo type=SYSCALL msg=audit(07/26/2023 07:22:13.392:2480) : arch=x86_64 syscall=openat success=no exit=EACCES(Permission denied) a0=AT_FDCWD a1=0x55648f0250b0 a2=O_RDWR|O_CREAT|O_EXCL a3=0x180 items=0 ppid=40948 pid=40952 auid=unset uid=unknown(1001) gid=unknown(1001) euid=unknown(1001) suid=unknown(1001) fsuid=unknown(1001) egid=unknown(1001) sgid=unknown(1001) fsgid=unknown(1001) tty=(none) ses=unset comm=Pdfprint.sh exe=/usr/bin/bash subj=system_u:system_r:winbind_rpcd_t:s0 key=(null) SYSCALL=openat AUID="unset" UID="smbuser" GID="smbuser" EUID="smbuser" SUID="smbuser" FSUID="smbuser" EGID="smbuser" SGID="smbuser" FSGID="smbuser" type=AVC msg=audit(07/26/2023 07:22:13.392:2480) : avc: denied { write } for pid=40952 comm=Pdfprint.sh name=tmp dev="vda3" ino=17458889 scontext=system_u:system_r:winbind_rpcd_t:s0 tcontext=system_u:object_r:tmp_t:s0 tclass=dir permissive=0
- Loading branch information