mirror of
https://github.com/SELinuxProject/refpolicy
synced 2025-02-15 19:37:11 +00:00
Update entropyd_t with privileges needed for haveged
Haveged by itself requires a few additional privileges (create a unix socket and write access to some proc/sys/kernel files (like /proc/sys/kernel/random/write_wakeup_threshold). Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
This commit is contained in:
parent
34aea93484
commit
62cdea27c3
@ -27,11 +27,12 @@ files_pid_file(entropyd_var_run_t)
|
||||
allow entropyd_t self:capability { dac_override ipc_lock sys_admin };
|
||||
dontaudit entropyd_t self:capability sys_tty_config;
|
||||
allow entropyd_t self:process signal_perms;
|
||||
allow entropyd_t self:unix_dgram_socket create_socket_perms;
|
||||
|
||||
manage_files_pattern(entropyd_t, entropyd_var_run_t, entropyd_var_run_t)
|
||||
files_pid_filetrans(entropyd_t, entropyd_var_run_t, file)
|
||||
|
||||
kernel_read_kernel_sysctls(entropyd_t)
|
||||
kernel_rw_kernel_sysctl(entropyd_t)
|
||||
kernel_list_proc(entropyd_t)
|
||||
kernel_read_proc_symlinks(entropyd_t)
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user