Merge pull request #217 from bauen1/init-confined-keyring
This commit is contained in:
commit
782cd81a4b
|
@ -239,6 +239,7 @@ ifdef(`init_systemd',`
|
||||||
allow init_t self:netlink_route_socket create_netlink_socket_perms;
|
allow init_t self:netlink_route_socket create_netlink_socket_perms;
|
||||||
allow init_t initrc_t:unix_dgram_socket create_socket_perms;
|
allow init_t initrc_t:unix_dgram_socket create_socket_perms;
|
||||||
allow init_t self:capability2 audit_read;
|
allow init_t self:capability2 audit_read;
|
||||||
|
allow init_t self:key { search setattr write };
|
||||||
allow init_t self:bpf { map_create map_read map_write prog_load prog_run };
|
allow init_t self:bpf { map_create map_read map_write prog_load prog_run };
|
||||||
|
|
||||||
allow init_t init_mountpoint_type:dir_file_class_set { getattr mounton };
|
allow init_t init_mountpoint_type:dir_file_class_set { getattr mounton };
|
||||||
|
@ -300,6 +301,7 @@ ifdef(`init_systemd',`
|
||||||
kernel_unmount_debugfs(init_t)
|
kernel_unmount_debugfs(init_t)
|
||||||
kernel_search_key(init_t)
|
kernel_search_key(init_t)
|
||||||
kernel_setsched(init_t)
|
kernel_setsched(init_t)
|
||||||
|
kernel_link_key(init_t)
|
||||||
kernel_rw_unix_sysctls(init_t)
|
kernel_rw_unix_sysctls(init_t)
|
||||||
|
|
||||||
# run systemd misc initializations
|
# run systemd misc initializations
|
||||||
|
|
Loading…
Reference in New Issue