fedora-cosmic: ship SELinux policy for kanidm-unixd sockets
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m3s

nss/pam consumers (sshd, the display manager, systemd-userdbd, polkit, ...)
were denied write access to /run/kanidm-unixd/* (var_run_t), so Kanidm users
could not be resolved or authenticated and logins failed with 'invalid user'.
Add the audit2allow-derived CIL and load it at build time (semodule noreload).
This commit is contained in:
2026-09-27 18:49:12 +02:00
parent a5c6170ac0
commit f00f4340b7
2 changed files with 30 additions and 0 deletions
+9
View File
@@ -46,6 +46,7 @@ add-files:
- ["kanidm-password-auth", "/usr/share/fedora-cosmic/authselect/password-auth"]
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
postprocess:
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
@@ -88,6 +89,14 @@ postprocess:
install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf /etc/nsswitch.conf
fi
# Kanidm has no SELinux policy; install ours so nss/pam consumers (sshd,
# the display manager, systemd-userdbd, ...) can reach the kanidm-unixd
# sockets and resolve Kanidm users.
- |
#!/usr/bin/env bash
set -xeuo pipefail
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
- |
#!/usr/bin/env bash
@@ -0,0 +1,21 @@
; Kanidm ships no SELinux policy. Without these allows, nss/pam consumers
; (sshd, the display manager, systemd-userdbd, ...) are denied write access to
; the kanidm-unixd sockets in /run/kanidm-unixd (labeled var_run_t), so Kanidm
; users cannot be resolved or authenticated and logins fail (sshd reports
; "invalid user"). This is the allow set produced by:
; grep avc: /var/log/audit/audit.log | audit2allow
(allow accountsd_t var_run_t (sock_file (write)))
(allow auditd_t var_run_t (sock_file (write)))
(allow chkpwd_t var_run_t (sock_file (write)))
(allow local_login_t var_run_t (sock_file (write)))
(allow policykit_t var_run_t (sock_file (write)))
(allow ssh_keygen_t var_run_t (sock_file (write)))
(allow sshd_auth_t var_run_t (sock_file (write)))
(allow sshd_keygen_t var_run_t (sock_file (write)))
(allow sshd_session_t var_run_t (sock_file (write)))
(allow sshd_t var_run_t (sock_file (write)))
(allow systemd_bootc_generator_t var_run_t (sock_file (write)))
(allow systemd_selinux_autorelabel_generator_t var_run_t (sock_file (write)))
(allow systemd_userdbd_t var_run_t (sock_file (write)))
(allow xdm_t var_run_t (sock_file (write)))
(allow init_t unconfined_service_t (unix_stream_socket (connectto)))