How to add applications in allow list using fapolicyd in RHEL ?

Solution Verified - Updated -

Issue

  • Why is the fapolicyd service blocking command execution in RHEL?

  • When fapolicyd is running, the third party application commands fails to execute. However the third party application functions when the fapolicyd service is stopped.

  • User cannot execute operations (e.g. read) on certain files even though the ownership and permissions appear to be correct. Instead, user receives an 'Operation not permitted' message.

  • How to add a binary such as /tmp/ls or binaries in directory /tmp/ in allow list through fapolicyd when the debug output is reporting deny_audit events as shown as below :

    # cat fapolicy.output | grep 'deny_audit'
    ...
    rule=13 dec=deny_audit perm=execute auid=0 pid=6855 exe=/usr/bin/bash : path=/tmp/ls ftype=application/x-executable trust=0
    

Environment

  • Red Hat Enterprise Linux 8
  • Red Hat Enterprise Linux 9
  • fapolicyd

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content