rpc: add dac_read_search capability for rpcd_t
Fixes: avc: denied { dac_read_search } for pid=473 comm="sm-notify" capability=2 scontext=system_u:system_r:rpcd_t tcontext=system_u:system_r:rpcd_t tclass=capability permissive=1 Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
This commit is contained in:
parent
6a3bba766f
commit
a7700d9bb7
@ -232,7 +232,7 @@ optional_policy(`
|
||||
# Local policy
|
||||
#
|
||||
|
||||
allow rpcd_t self:capability { chown dac_override setgid setpcap setuid sys_admin };
|
||||
allow rpcd_t self:capability { chown dac_override dac_read_search setgid setpcap setuid sys_admin };
|
||||
allow rpcd_t self:capability2 block_suspend;
|
||||
allow rpcd_t self:process { getcap setcap };
|
||||
allow rpcd_t self:fifo_file rw_fifo_file_perms;
|
||||
|
Loading…
Reference in New Issue
Block a user