Layman (running in portage_fetch_t) in some cases needs access to /var/lib/gentoo/news (creating a lockfile). This location is currently var_lib_t. We probably need to make this its own file type, and then grant the proper portage domains access to it. Reproducible: Always
(In reply to Sven Vermeulen from comment #0) > Layman (running in portage_fetch_t) in some cases needs access to > /var/lib/gentoo/news (creating a lockfile). This location is currently > var_lib_t. how do you trigger this? > We probably need to make this its own file type, and then grant the proper > portage domains access to it. this already exists: /var/lib/portage(/.*)? gen_context(system_u:object_r:portage_cache_t,s0) perhaps just re-use portage_cache_t for /var/lib/gentoo too?