Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SELinux policy rules allowing to access /proc/sys/fs/nr_open #1918

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

grulja
Copy link
Contributor

@grulja grulja commented Feb 27, 2025

This is needed when the nofile limit is set to unlimited, otherwise we will fail to start a VNC session.

This is needed when the nofile limit is set to unlimited, otherwise we
will fail to start a VNC session.
@grulja
Copy link
Contributor Author

grulja commented Feb 27, 2025

This is supposed to fix https://issues.redhat.com/browse/RHEL-77973. I tested this with both a regular and root users.

You can reproduce it by setting nofile limit to unlimited in /etc/security/limits.conf.

CC @zpytela: your feedback is also appreciated.

@CendioOssman
Copy link
Member

Thanks for the fix!

It is a bit non-SPOT that every service used by PAM has to duplicate permissions like this. Is there any work being done to provide an interface macro that coordinates permissions that PAM-modules might need? Probably a question for @zpytela rather than @grulja.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants