systemd: allow systemd-rfkill to getopt from uevent sockets
Fixes: avc: denied { getopt } for pid=313 comm="systemd-rfkill" scontext=system_u:system_r:systemd_rfkill_t:s0-s15:c0.c1023 tcontext=system_u:system_r:systemd_rfkill_t:s0-s15:c0.c1023 tclass=netlink_kobject_uevent_socket permissive=1 Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
This commit is contained in:
parent
ecc6e3ccde
commit
9d3513c7fa
@ -1513,7 +1513,7 @@ logging_send_syslog_msg(systemd_pstore_t)
|
||||
# Rfkill local policy
|
||||
#
|
||||
|
||||
allow systemd_rfkill_t self:netlink_kobject_uevent_socket { bind create getattr read setopt };
|
||||
allow systemd_rfkill_t self:netlink_kobject_uevent_socket { bind create getattr read getopt setopt };
|
||||
|
||||
manage_dirs_pattern(systemd_rfkill_t, systemd_rfkill_var_lib_t, systemd_rfkill_var_lib_t)
|
||||
manage_files_pattern(systemd_rfkill_t, systemd_rfkill_var_lib_t, systemd_rfkill_var_lib_t)
|
||||
|
Loading…
Reference in New Issue
Block a user