1
0
mirror of https://github.com/SELinuxProject/refpolicy synced 2025-03-25 04:26:37 +00:00
selinux-refpolicy/policy/modules
Krzysztof Nowicki 9b8c2d5393 Allow systemd to relabel cgroupfs legacy symlinks
The cgroup directory under /sys/fs/cgroup contains a number of
pseudo-filesystems for each cgroup as well as two symbolic links for the
cpu and cpuacct groups, which were legacy symbolic links to the
cpu,cpuacct group.

These rules allow systemd to relabel these symbolic links from tmpfs_t
to their proper context, or otherwise denials will be printed for nearly
all systemd operation involving cgroups.

This change only grants systemd the possibility to relabel the
files. The actual relabelling needs to be done by systemd. The
accompanying change (commit 8739f23) will be released with systemd v236.
2017-12-01 18:48:26 -05:00
..
admin dmesg, locallogin, modutils: Module version bump. 2017-11-18 07:32:37 -05:00
apps Bump module versions for release. 2017-08-05 12:59:42 -04:00
contrib@2534d68148 networkmanager: Grant access to unlabeled PKeys 2017-11-28 20:46:26 -05:00
kernel Allow systemd to relabel cgroupfs legacy symlinks 2017-12-01 18:48:26 -05:00
roles kernel, mls, sysadm, ssh, xserver, authlogin, locallogin, userdomain: Module version bumps. 2017-11-04 14:16:20 -04:00
services Module version bumps. 2017-11-14 18:33:06 -05:00
system Allow systemd to relabel cgroupfs legacy symlinks 2017-12-01 18:48:26 -05:00