From 0f4eb2a324f7c5e1d618b7035377525bddcd75f2 Mon Sep 17 00:00:00 2001 From: bauen1 Date: Sat, 16 May 2020 22:25:40 +0200 Subject: [PATCH] init: fix systemd boot Signed-off-by: bauen1 --- policy/modules/system/init.te | 1 + policy/modules/system/logging.if | 19 +++++++++++++++++++ 2 files changed, 20 insertions(+) diff --git a/policy/modules/system/init.te b/policy/modules/system/init.te index cc9438ce5..29dd74633 100644 --- a/policy/modules/system/init.te +++ b/policy/modules/system/init.te @@ -447,6 +447,7 @@ ifdef(`init_systemd',` logging_relabelto_devlog_sock_files(init_t) logging_relabel_generic_log_dirs(init_t) logging_audit_socket_activation(init_t) + logging_use_syslogd_fd(init_t) # lvm2-activation-generator checks file labels seutil_read_file_contexts(init_t) diff --git a/policy/modules/system/logging.if b/policy/modules/system/logging.if index 4223e6b76..583b873a4 100644 --- a/policy/modules/system/logging.if +++ b/policy/modules/system/logging.if @@ -687,6 +687,25 @@ interface(`logging_send_syslog_msg',` ') ') +######################################## +## +## Allow domain to use a file descriptor +## from syslogd. +## +## +## +## Domain allowed access. +## +## +# +interface(`logging_use_syslogd_fd', ` + gen_require(` + type syslogd_t; + ') + + allow $1 syslogd_t:fd use; +') + ######################################## ## ## Allow domain to relabelto devlog sock_files