From c1a352a615c3c365d7953a8a2fd65fdbad61e955 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Tue, 17 Jan 2023 08:36:58 -0500 Subject: [PATCH] systemd: Tmpfilesd can correct seusers on files. Signed-off-by: Chris PeBenito --- policy/modules/system/systemd.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index 1b2a7c022..5da67ea83 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -1646,6 +1646,8 @@ dev_setattr_all_sysfs(systemd_tmpfiles_t) # /sys/module/kernel/parameters/crash_kexec_post_notifiers dev_write_sysfs(systemd_tmpfiles_t) +domain_obj_id_change_exemption(systemd_tmpfiles_t) + files_create_lock_dirs(systemd_tmpfiles_t) files_dontaudit_getattr_all_dirs(systemd_tmpfiles_t) files_manage_all_runtime_dirs(systemd_tmpfiles_t)