Skip to content

Support sshd_session_t SELinux domain in installer - #614

Open
ozan956 wants to merge 1 commit into
openpubkey:mainfrom
ozan956:fix/selinux-sshd-session-domain
Open

Support sshd_session_t SELinux domain in installer#614
ozan956 wants to merge 1 commit into
openpubkey:mainfrom
ozan956:fix/selinux-sshd-session-domain

Conversation

@ozan956

@ozan956 ozan956 commented Sep 4, 2026

Copy link
Copy Markdown

opkssh.te only grants permissions to the sshd_t domain, and install-linux.sh always builds/loads the module for sshd_t unconditionally. Some SELinux policies instead run sshd's AuthorizedKeysCommand under sshd_session_t, so on those systems the installed policy denies opkssh the access it needs.

install-linux.sh now tries loading the module against sshd_session_t first; if the target's loaded policy doesn't define that type, the load fails and it falls back to the sshd_t module. The choice is based on what the loaded policy actually supports, so it works across distros/versions without hardcoding any of them.

Fixes: #599

@ozan956

ozan956 commented Sep 4, 2026

Copy link
Copy Markdown
Author

Tested on my local setup but lets see how CI goes.

opkssh.te only grants permissions to the sshd_t domain, and
install-linux.sh always builds/loads the module for sshd_t
unconditionally. Some SELinux policies instead run sshd's
AuthorizedKeysCommand under sshd_session_t, so on those systems the
installed policy denies opkssh the access it needs.

install-linux.sh now tries loading the module against sshd_session_t
first; if the target's loaded policy doesn't define that type, the
load fails and it falls back to the sshd_t module. The choice is based
on what the loaded policy actually supports, so it works across
distros/versions without hardcoding any of them.

Fixes: openpubkey#599
Signed-off-by: Ozan Durgut <ozan.durgut@analog.com>
@ozan956
ozan956 force-pushed the fix/selinux-sshd-session-domain branch from 538d42d to ead29ed Compare September 4, 2026 11:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Breaking selinux-policy-42.1.18-4.el10_2.2 on RHEL10

1 participant