allow kdm to create /root/.kde/ with correct label #2474
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
When the kdm service is started, it wants to create the .kde directory under /root/, but SELinux denies that action. When the /root/.kde directory exists, the kdm service wants to create a symlink in it, but SELinux denies that action too. The intended symlink should point this way:
The fix has 2 parts. First, SELinux policy should label the newly created /root/.kde directory correctly (xdm_home_t). Second, SELinux policy should allow the kdm initiated process to create a symlink in that directory.
Resolves: bz#2275868