What were you trying to do that didn't work?
During our work on RHEL Image Mode Compliance, we have discovered an issue with "/run/fapolicyd" file mode and groupownership. However, the issue is also present in a normal RHEL (not image mode).
What is the impact of this issue to you?
This problem will be flagged by OpenSCAP scans of profiles that contain rule "rpm_verify_permissions".
Please provide the package NVR for which the bug is seen:
fapolicyd-1.3.3-100.el9.x86_64
How reproducible is this bug?:
deterministic
Steps to reproduce
- dnf -y install fapolicyd
- systemctl enable --now fapolicyd
- rpm -V fapolicyd
Expected results
the file /run/fapolicyd doesn't differ from RPM expectation
Actual results
rpm -V fapolicyd
.M....G.. /run/fapolicyd