<feed xmlns='http://www.w3.org/2005/Atom'>
<title>guix/etc/guix-daemon.cil.in, branch sysadmin-team</title>
<subtitle>Transactional package manager, declarative GNU/Linux distribution, reproducible deployment tool, and more! https://guix.gnu.org</subtitle>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/'/>
<entry>
<title>etc: SELinux: Add permissions to allow garbage collection.</title>
<updated>2025-12-15T20:53:21+00:00</updated>
<author>
<name>Thiago Jung Bauermann</name>
<email>bauermann@kolabnow.com</email>
</author>
<published>2025-12-08T04:35:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=53808b13b8c91826a0871bf49a9957b8228c4086'/>
<id>53808b13b8c91826a0871bf49a9957b8228c4086</id>
<content type='text'>
There may be an improvement to be made to guix-daemon to avoid some
spurious denial audit messages, as described in the FIXME.

* etc/guix-daemon.cil.in: Add missing rules for guix gc.

Change-Id: I3651c4523528649048c7135fabd3000c8e78b1ff
Signed-off-by: Rutherther &lt;rutherther@ditigal.xyz&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
There may be an improvement to be made to guix-daemon to avoid some
spurious denial audit messages, as described in the FIXME.

* etc/guix-daemon.cil.in: Add missing rules for guix gc.

Change-Id: I3651c4523528649048c7135fabd3000c8e78b1ff
Signed-off-by: Rutherther &lt;rutherther@ditigal.xyz&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: SELinux: Add missing permissions.</title>
<updated>2025-12-15T20:53:17+00:00</updated>
<author>
<name>Thiago Jung Bauermann</name>
<email>bauermann@kolabnow.com</email>
</author>
<published>2025-12-08T03:12:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=1b59b93602d034d75882b0ca076a732cd1865d98'/>
<id>1b59b93602d034d75882b0ca076a732cd1865d98</id>
<content type='text'>
With the changes in this commit, I can use "guix pull" and
"guix install &lt;package&gt;" successfully and without generating SELinux
denial erros in the system log.

* etc/guix-daemon.cil.in: Add missing rules for guix pull/guix install.

Change-Id: I40b5ed2c458b275804bc073fb72286947ecb0283
Signed-off-by: Rutherther &lt;rutherther@ditigal.xyz&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
With the changes in this commit, I can use "guix pull" and
"guix install &lt;package&gt;" successfully and without generating SELinux
denial erros in the system log.

* etc/guix-daemon.cil.in: Add missing rules for guix pull/guix install.

Change-Id: I40b5ed2c458b275804bc073fb72286947ecb0283
Signed-off-by: Rutherther &lt;rutherther@ditigal.xyz&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: Update SELinux rule file to support unprivileged daemon.</title>
<updated>2025-12-05T13:54:39+00:00</updated>
<author>
<name>Rutherther</name>
<email>rutherther@ditigal.xyz</email>
</author>
<published>2025-11-29T16:58:54+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=bd2edc9e435402b48fd201b56ab486151512717a'/>
<id>bd2edc9e435402b48fd201b56ab486151512717a</id>
<content type='text'>
Fixes: #3576.

* etc/guix-daemon.cil.in: Add rules for unprivileged daemon.

Change-Id: Ic0c561036230d397f7071daef33ca8181684d014
Signed-off-by: Ludovic Courtès &lt;ludo@gnu.org&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fixes: #3576.

* etc/guix-daemon.cil.in: Add rules for unprivileged daemon.

Change-Id: Ic0c561036230d397f7071daef33ca8181684d014
Signed-off-by: Ludovic Courtès &lt;ludo@gnu.org&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: SELinux: Update policy file.</title>
<updated>2023-05-25T10:51:15+00:00</updated>
<author>
<name>Ludovic Courtès</name>
<email>ludo@gnu.org</email>
</author>
<published>2023-05-25T09:37:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=3bf612eaa13cc39caab64567660b8a02d206d19a'/>
<id>3bf612eaa13cc39caab64567660b8a02d206d19a</id>
<content type='text'>
Tested on Rocky Linux 9, as discussed
at &lt;https://issues.guix.gnu.org/62487&gt;.

* etc/guix-daemon.cil.in: Add rules for /gnu/store remount and file
creation in /tmp.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Tested on Rocky Linux 9, as discussed
at &lt;https://issues.guix.gnu.org/62487&gt;.

* etc/guix-daemon.cil.in: Add rules for /gnu/store remount and file
creation in /tmp.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: SELinux: Allow init process to setattr on profile directories.</title>
<updated>2022-12-23T19:20:06+00:00</updated>
<author>
<name>Ricardo Wurmus</name>
<email>rekado@elephly.net</email>
</author>
<published>2022-12-23T15:48:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=afaeb657b118e6998342110deab8c8110b824417'/>
<id>afaeb657b118e6998342110deab8c8110b824417</id>
<content type='text'>
* etc/guix-daemon.cil.in: Add rule.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in: Add rule.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: SELinux: Allow daemon to search run state directories.</title>
<updated>2022-12-23T19:20:06+00:00</updated>
<author>
<name>Ricardo Wurmus</name>
<email>rekado@elephly.net</email>
</author>
<published>2022-12-23T15:47:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=4a134ed32e69ba888d988d2ed924a1531a54551b'/>
<id>4a134ed32e69ba888d988d2ed924a1531a54551b</id>
<content type='text'>
* etc/guix-daemon.cil.in: Import types init_var_run_t and
system_dbusd_var_run_t; add rules.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in: Import types init_var_run_t and
system_dbusd_var_run_t; add rules.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: SELinux: Label guix-daemon executable in profile.</title>
<updated>2022-12-23T19:20:06+00:00</updated>
<author>
<name>Ricardo Wurmus</name>
<email>rekado@elephly.net</email>
</author>
<published>2022-12-23T15:44:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=f28d792719abb82cc920486e6d6f14eacc44370c'/>
<id>f28d792719abb82cc920486e6d6f14eacc44370c</id>
<content type='text'>
* etc/guix-daemon.cil.in: Add file rule for "guix-daemon" in current-guix
profile.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in: Add file rule for "guix-daemon" in current-guix
profile.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: Remove redundant SELinux permissions block.</title>
<updated>2022-01-26T08:31:45+00:00</updated>
<author>
<name>Marius Bakke</name>
<email>marius@gnu.org</email>
</author>
<published>2022-01-24T10:53:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=bbc2fb0d52128c85c92251ed36d8063b3dcf3c3a'/>
<id>bbc2fb0d52128c85c92251ed36d8063b3dcf3c3a</id>
<content type='text'>
* etc/guix-daemon.cil.in (guix_daemon): Consolidate two blocks adding
sock_file permissions on guix_daemon_conf_t.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in (guix_daemon): Consolidate two blocks adding
sock_file permissions on guix_daemon_conf_t.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: Add more SELinux permissions for the daemon.</title>
<updated>2022-01-24T10:28:14+00:00</updated>
<author>
<name>Marius Bakke</name>
<email>marius@gnu.org</email>
</author>
<published>2022-01-24T10:26:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=98e74d520a30d1ed7d7b47d4f1d9afadefc699e3'/>
<id>98e74d520a30d1ed7d7b47d4f1d9afadefc699e3</id>
<content type='text'>
* etc/guix-daemon.cil.in (guix_daemon): Permit write on guix_daemon_conf_t
sock_file, necessary for garbage collection.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in (guix_daemon): Permit write on guix_daemon_conf_t
sock_file, necessary for garbage collection.
</pre>
</div>
</content>
</entry>
<entry>
<title>etc: Add more SELinux permissions for the daemon.</title>
<updated>2021-05-22T17:53:17+00:00</updated>
<author>
<name>Marius Bakke</name>
<email>marius@gnu.org</email>
</author>
<published>2021-05-22T17:42:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.vineetk.net/guix/commit/?id=35bd94a49257bbadcb3ca25342e5c1ec33f438f0'/>
<id>35bd94a49257bbadcb3ca25342e5c1ec33f438f0</id>
<content type='text'>
* etc/guix-daemon.cil.in (guix_daemon): Add more permissions, necessary for
garbage collection.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* etc/guix-daemon.cil.in (guix_daemon): Add more permissions, necessary for
garbage collection.
</pre>
</div>
</content>
</entry>
</feed>
