Support flushing routing cache
To flush the routing cache, ifconfig_t (through the "ip" command) requires sys_admin capability. If not: ~# ip route flush cache Cannot flush routing cache Signed-off-by: Sven Vermeulen <sven.vermeulen@siphos.be>
This commit is contained in:
parent
d29f5d4e72
commit
7ed91bfafd
@ -243,7 +243,7 @@ optional_policy(`
|
||||
# Ifconfig local policy
|
||||
#
|
||||
|
||||
allow ifconfig_t self:capability { net_raw net_admin sys_tty_config };
|
||||
allow ifconfig_t self:capability { net_raw net_admin sys_admin sys_tty_config };
|
||||
allow ifconfig_t self:process ~{ ptrace setcurrent setexec setfscreate setrlimit execmem execheap execstack };
|
||||
allow ifconfig_t self:fd use;
|
||||
allow ifconfig_t self:fifo_file rw_fifo_file_perms;
|
||||
|
Loading…
Reference in New Issue
Block a user