diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if index f9fd09b73..2415bb771 100644 --- a/policy/modules/system/init.if +++ b/policy/modules/system/init.if @@ -99,6 +99,12 @@ interface(`init_script_domain',` role system_r types $1; domtrans_pattern(init_run_all_scripts_domain, $2, $1) + + ifdef(`init_systemd',` + allow $1 init_t:unix_stream_socket { getattr read write ioctl }; + + allow init_t $1:process2 { nnp_transition nosuid_transition }; + ') ') ########################################