selinux-refpolicy/policy/modules
Nicolas Iooss 233e13cb44
systemd: allow systemd-modules-load.service to read sysfs
systemd-modules-load.service needs to read file
/sys/module/${MODULE}/initstate for each ${MODULE} defined in
/etc/modules-load.d/. These files are labeled sysfs_t.

This fixes:

    type=AVC msg=audit(1567804818.331:138713): avc:  denied  { read }
    for  pid=31153 comm="systemd-modules" name="initstate" dev="sysfs"
    ino=14778 scontext=system_u:system_r:systemd_modules_load_t
    tcontext=system_u:object_r:sysfs_t tclass=file permissive=0

Signed-off-by: Nicolas Iooss <nicolas.iooss@m4x.org>
2019-09-06 23:28:40 +02:00
..
admin Various: Module version bump. 2019-08-31 06:55:57 -04:00
apps various: Module version bump. 2019-09-03 19:47:12 -04:00
kernel various: Module version bump. 2019-09-03 19:47:12 -04:00
roles rpm, selinux, sysadm, init: Module version bump. 2019-07-13 14:07:11 -04:00
services various: Module version bump. 2019-09-03 19:47:12 -04:00
system systemd: allow systemd-modules-load.service to read sysfs 2019-09-06 23:28:40 +02:00