Skip to content

enable-aslr can't take inventory on selinux enabled systems? #65

@craigcomstock

Description

@craigcomstock

I added the enable-aslr module and noticed my rhel-8 system wasn't reporting the inventory "Address space layout randomization (ASLR)"

I see in /var/log/audit/audit.log

type=AVC msg=audit(1670539759.037:969): avc:  denied  { getattr } for  pid=21441 comm="cf-promises" path="/proc/sys/kernel/randomize_va_space" dev="proc" ino=37714 scontext=system_u:system_r:cfengine_execd_t:s0 tcontext=system_u:object_r:proc_security_t:s0 tclass=file permissive=0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions