Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Dontaudit systemd-logind remove all files
When a user login session ends, "systemd-user-runtime-dir stop" is executed as an ExecStop action of the [email protected]. The command tries to delete the content of /run/user/UID, containing user data with possibly any SELinux type, using an equivalent of the "rm -rf" command. This is more like a safety action because the /run/user/UID directory is a tmpfs mount and is unmounted afterwards anyway, therefore the systemd_logind_t domain does not actually need the access to read directories and unlink files of all types, so the permissions are dontaudited instead. Resolves: RHEL-59145
- Loading branch information