Re: avc: denied { search } for smbd

Felipe Alfaro Solana wrote:

On 23 Apr 2005, at 14:25, Ivan Gyurdiev wrote:

So I don't understand what's going on: the policy explicitly allows
domain smbd_t to perform search on home_root_t:dir and /home is already
labeled home_root_t.

Yes, but it only does this when samba_enable_home_dirs is on.

Toggle the boolean.

I have manually added the following line to /etc/selinux/targeted/booleans.local


but now, I'm getting these avc's:

audit(1114271834.460:0): avc: denied { getattr } for path=/dev/pts dev=devpts ino=1 scontext=user_u:system_r:smbd_t tcontext=user_u:object_r:devpts_t tclass=dir

Is this causing it to fail or is this just being reported in the log files and ignored?

More ideas?

