Re: [gentoo-hardened] SELinux cronjobs in wrong context?

2017-01-31 Thread Robert Sharp
On 31/01/17 03:48, Jason Zaman wrote: As a workaround, you can echo "system_u:system_u:s0-s0:c0.c1023" >> /etc/selinux/mcs/seusers you cant use semanage to add it since system_u isnt a valid user, and you'll have to re-add that after loading modules since the file is re-generated. after adding

Re: [gentoo-hardened] SELinux cronjobs in wrong context?

2017-01-30 Thread Jason Zaman
On Mon, Jan 30, 2017 at 10:35:18PM +, Robert Sharp wrote: > Just when I thought I was getting near to switching on strict and all of > a sudden my cron jobs are throwing AVCs all over. > > > The gist of it is all the same, for example: > scontext=user_u:user_r:cronjob_t