raid: allow mdadm to read udev runtime files

This fixes this AVC:

avc:  denied  { getattr } for  pid=2238 comm="mdadm" path="/run/udev" dev="tmpfs" ino=52 scontext=system_u:system_r:mdadm_t:s0 tcontext=system_u:object_r:udev_runtime_t:s0 tclass=dir permissive=0

Signed-off-by: Kenton Groombridge <me@concord.sh>
This commit is contained in:
Kenton Groombridge 2023-03-06 10:28:22 -05:00
parent edef7a8469
commit 69e6c33c46

View File

@ -85,6 +85,8 @@ logging_send_syslog_msg(mdadm_t)
miscfiles_read_localization(mdadm_t)
udev_read_runtime_files(mdadm_t)
userdom_use_user_terminals(mdadm_t)
userdom_dontaudit_use_unpriv_user_fds(mdadm_t)
userdom_dontaudit_search_user_home_content(mdadm_t)