fedora-cosmic: ship SELinux policy for kanidm-unixd sockets
Build containers / fedora-cosmic (rawhide) (push) Failing after 50s
Build containers / fedora-cosmic (44) (push) Successful in 11m3s

nss/pam consumers (sshd, the display manager, systemd-userdbd, polkit, ...)
were denied write access to /run/kanidm-unixd/* (var_run_t), so Kanidm users
could not be resolved or authenticated and logins failed with 'invalid user'.
Add the audit2allow-derived CIL and load it at build time (semodule noreload).
This commit is contained in:
2026-09-27 18:49:12 +02:00
parent a5c6170ac0
commit f00f4340b7
2 changed files with 30 additions and 0 deletions
+9
View File
@@ -46,6 +46,7 @@ add-files:
- ["kanidm-password-auth", "/usr/share/fedora-cosmic/authselect/password-auth"]
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
postprocess:
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
@@ -88,6 +89,14 @@ postprocess:
install -m 0644 /usr/share/fedora-cosmic/authselect/nsswitch.conf /etc/nsswitch.conf
fi
# Kanidm has no SELinux policy; install ours so nss/pam consumers (sshd,
# the display manager, systemd-userdbd, ...) can reach the kanidm-unixd
# sockets and resolve Kanidm users.
- |
#!/usr/bin/env bash
set -xeuo pipefail
semodule -n -i /usr/share/fedora-cosmic/kanidm-unixd.cil
# Kanidm does not ship an SELinux policy yet; let the unixd daemons run.
- |
#!/usr/bin/env bash