If you believe that boltd should be allowed getattr access on the 8ADB159E-1E32-455C-BC93-308A7ED98246 lnk_file by default.
Then you should report this as a bug.
You can generate a local policy module to allow this access.
Do
allow this access for now by executing:
This update has been submitted for testing by lvrabec.
This update's test gating status has been changed to 'waiting'.
This update's test gating status has been changed to 'ignored'.
This update has been pushed to testing.
Not giving karma, but see below.
SELinux is preventing boltd from getattr access on the lnk_file /sys/bus/wmi/devices/8ADB159E-1E32-455C-BC93-308A7ED98246.
* Plugin catchall (100. confidence) suggests ******
If you believe that boltd should be allowed getattr access on the 8ADB159E-1E32-455C-BC93-308A7ED98246 lnk_file by default. Then you should report this as a bug. You can generate a local policy module to allow this access. Do allow this access for now by executing:
ausearch -c 'boltd' --raw | audit2allow -M my-boltd
semodule -X 300 -i my-boltd.pp
Additional Information: Source Context system_u:system_r:boltd_t:s0 Target Context system_u:object_r:sysfs_t:s0 Target Objects /sys/bus/wmi/devices/8ADB159E-1E32-455C-BC93-308A7 ED98246 [ lnk_file ] Source boltd Source Path boltd Port <Unknown> Host <host> Source RPM Packages
Target RPM Packages
Policy RPM selinux-policy-3.14.3-48.fc30.noarch Selinux Enabled True Policy Type targeted Enforcing Mode Enforcing Host Name <host> Platform Linux <host> 5.2.18-200.fc30.x86_64 #1 SMP Tue Oct 1 13:14:07 UTC 2019 x86_64 x86_64 Alert Count 15 First Seen 2019-10-05 18:59:37 AEST Last Seen 2019-10-05 18:59:37 AEST Local ID fb46027c-2279-40e2-a8f7-feaa3308cc79
Raw Audit Messages type=AVC msg=audit(1570265977.494:204): avc: denied { getattr } for pid=2436 comm="boltd" path="/sys/bus/wmi/devices/8ADB159E-1E32-455C-BC93-308A7ED98246" dev="sysfs" ino=18891 scontext=system_u:system_r:boltd_t:s0 tcontext=system_u:object_r:sysfs_t:s0 tclass=lnk_file permissive=0
Hash: boltd,boltd_t,sysfs_t,lnk_file,getattr
This update's test gating status has been changed to 'greenwave_failed'.
This update's test gating status has been changed to 'ignored'.
lvrabec edited this update.
New build(s):
Removed build(s):
Karma has been reset.
This update has been submitted for testing by lvrabec.
This update has been pushed to testing.
No issues noted on hardware or KVM guest.
No issues noted.
This update can be pushed to stable now if the maintainer wishes
This update has been obsoleted by selinux-policy-3.14.3-50.fc30.