diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index 43673a4e0..6e999b662 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -1181,21 +1181,21 @@ allow systemd_socket_proxyd_t self:tcp_socket accept; kernel_read_system_state(systemd_socket_proxyd_t) auth_use_nsswitch(systemd_socket_proxyd_t) + sysnet_dns_name_resolve(systemd_socket_proxyd_t) tunable_policy(`systemd_socket_proxyd_bind_any',` - corenet_tcp_bind_all_ports(systemd_socket_proxyd_t) + corenet_tcp_bind_all_ports(systemd_socket_proxyd_t) ',` - allow systemd_socket_proxyd_t systemd_socket_proxyd_port_t:tcp_socket name_bind; + allow systemd_socket_proxyd_t systemd_socket_proxyd_port_t:tcp_socket name_bind; ') tunable_policy(`systemd_socket_proxyd_connect_any',` - corenet_tcp_connect_all_ports(systemd_socket_proxyd_t) + corenet_tcp_connect_all_ports(systemd_socket_proxyd_t) ',` - allow systemd_socket_proxyd_t systemd_socket_proxyd_port_t:tcp_socket name_connect; + allow systemd_socket_proxyd_t systemd_socket_proxyd_port_t:tcp_socket name_connect; ') - ######################################### # # Sessions local policy