From f71d288e54e8a67dedacd341f87918e8bc3c5e41 Mon Sep 17 00:00:00 2001 From: Antoine Tenart Date: Thu, 13 Aug 2020 11:52:20 +0200 Subject: [PATCH] systemd: add extra systemd_generator_t rules Fixes: avc: denied { setfscreate } for pid=41 comm="systemd-getty-g" scontext=system_u:system_r:systemd_generator_t tcontext=system_u:system_r:systemd_generator_t tclass=process permissive=1 avc: denied { dac_override } for pid=40 comm="systemd-fstab-g" capability=1 scontext=system_u:system_r:systemd_generator_t tcontext=system_u:system_r:systemd_generator_t tclass=capability permissive=1 Signed-off-by: Antoine Tenart --- policy/modules/system/systemd.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index 143064474..d0a852a27 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -362,6 +362,8 @@ seutil_search_default_contexts(systemd_coredump_t) # allow systemd_generator_t self:fifo_file rw_fifo_file_perms; +allow systemd_generator_t self:capability dac_override; +allow systemd_generator_t self:process setfscreate; corecmd_getattr_bin_files(systemd_generator_t)