From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.sws.net.au (smtp.sws.net.au [144.76.186.9]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9C2B027603F for ; Sat, 25 Jul 2026 06:35:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=144.76.186.9 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784961362; cv=none; b=hp/abcbUq7FY3PVQcyAcNg2vrCg/yQGDYas3G4CxFHDqut8+tuWh/nbw3uPmKamtqumXc3YS/k4oAkDx7REJbkAunCi+KW6BYUvHLe3+A7J8m7f0km+MomKjfezIh5LIZHUmBdZ3nIgpwlGTSINdkONCVkEnCGnctslSxaxNw6A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784961362; c=relaxed/simple; bh=unFlSKsqNZXmN+Vb9oKVhCB2xetv7ZXd0nXUUgkKxGg=; h=From:To:Subject:Date:Message-ID:MIME-Version:Content-Type; b=fRH3oBGz60WkKK6JKye9V0smCaV21A2qupiQfq1dkJ1dL/EGA5Wgp6H26rEaErMJ/7dwBxDC+hopyXePh0YWrnK1eMLViBkw/GaXfyJa5V4EXT45etIYPdnU0niVkKgrkkA+JQiwKf9GKaR3XX0hpU+KKvYN+jaO2tdOIiNsDX8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=coker.com.au; spf=pass smtp.mailfrom=coker.com.au; dkim=pass (1024-bit key) header.d=coker.com.au header.i=@coker.com.au header.b=amvFdwfm; arc=none smtp.client-ip=144.76.186.9 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=coker.com.au Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=coker.com.au Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=coker.com.au header.i=@coker.com.au header.b="amvFdwfm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=coker.com.au; s=2008; t=1784961351; bh=hF1h2d67qNX/hDicOdr7kAe4caHnOY+yQuAI+un1rCk=; l=2884; h=From:To:Subject:Date:From; b=amvFdwfm9kMD3iTpaUV8fmug62jVZeol1FeLwtKH+rOfJHI/L9KfXwxEDyA0jeQW9 iHMEAuK5PgkXSoDtIgOXZO73ugpvt2AQpUUurbztsg979LFGsPN00Sfi1IogMQSEDC EGoRiESyvcytANZDOrJTnFT3IY97V8ZsVyDSv/Sk= Received: from liv.coker.com.au (unknown [IPv6:2001:4479:6706:1e00:7ef2:3dbf:9b1b:921a]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) (Authenticated sender: russell@coker.com.au) by smtp.sws.net.au (Postfix) with ESMTPSA id D5A431B88D for ; Sat, 25 Jul 2026 16:35:50 +1000 (AEST) From: Russell Coker To: selinux-refpolicy@vger.kernel.org Subject: mpv and kitty terminal emulator on Wayland Date: Sat, 25 Jul 2026 16:35:41 +1000 Message-ID: <1968598.tdWV9SEqCh@dojacat> Precedence: bulk X-Mailing-List: selinux-refpolicy@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="utf-8" When a paste operation is triggered (middle click on video window) mpv is having it's file handle sent to kitty, presumably by the wayland system (KDE in this case). Denying this access can cause the source of the paste data (kitty in this case) to crash. Here's the logs for kitty: type=AVC msg=audit(1784959694.829:20780): avc: denied { use } for pid=4712 comm="kitty" path="pipe:[150412]" dev="pipefs" ino=150412 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fd permissive=0 type=AVC msg=audit(1784959694.861:20787): avc: denied { use } for pid=4282 comm="QThread" path="pipe:[149316]" dev="pipefs" ino=149316 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fd permissive=0 type=AVC msg=audit(1784959851.794:22406): avc: denied { use } for pid=17365 comm="kitty" path="pipe:[166960]" dev="pipefs" ino=166960 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fd permissive=0 type=AVC msg=audit(1784959851.822:22409): avc: denied { use } for pid=16312 comm="WaylandEventThr" path="pipe:[164719]" dev="pipefs" ino=164719 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fd permissive=0 type=AVC msg=audit(1784959876.318:22422): avc: denied { use } for pid=10585 comm="kitty" path="pipe:[165833]" dev="pipefs" ino=165833 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fd permissive=0 Here's the errors from Kitty: file descriptor expected, object (52), message send(sh) [7.945] [glfw error 65544]: Wayland: fatal display error: Invalid argument Here's the errors from Konsole: file descriptor expected, object (66), message send(sh) The Wayland connection experienced a fatal error: Invalid argument Here's the logs when the fd use is allowed: type=AVC msg=audit(1784960913.928:24443): avc: denied { write } for pid=25743 comm="WaylandEventThr" path="pipe:[188207]" dev="pipefs" ino=188207 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fifo_file permissive=0 type=AVC msg=audit(1784960913.964:24444): avc: denied { write } for pid=24950 comm="QThread" path="pipe:[190614]" dev="pipefs" ino=190614 scontext=etbe:user_r:user_t:s0-s0:c0.c1023 tcontext=etbe:user_r:mplayer_t:s0- s0:c0.c1023 tclass=fifo_file permissive=0 So it looks that for Wayland to work in the expected manner without programs crashing all the time we need to allow every Wayland client domain to use a fd from every other domain and to have fifo_file rw_inherited_fifo_file_perms access. Would it be possible to have a SE Linux aware clipboard program to mediate this? -- My Main Blog http://etbe.coker.com.au/ My Documents Blog http://doc.coker.com.au/