@@ -360,7 +360,7 @@ systemd_log_parse_environment(systemd_backlight_t)
360360# Allow systemd-backlight to write to /sys/class/backlight/*/brightness
361361dev_rw_sysfs(systemd_backlight_t)
362362
363- kernel_dontaudit_search_kernel_sysctl (systemd_backlight_t)
363+ kernel_read_kernel_sysctls (systemd_backlight_t)
364364
365365# for udev.conf
366366files_read_etc_files(systemd_backlight_t)
@@ -370,6 +370,9 @@ udev_read_runtime_files(systemd_backlight_t)
370370
371371files_search_var_lib(systemd_backlight_t)
372372
373+ fs_getattr_all_fs(systemd_backlight_t)
374+ fs_search_cgroup_dirs(systemd_backlight_t)
375+
373376# ######################################
374377#
375378# Binfmt local policy
@@ -469,7 +472,7 @@ seutil_search_default_contexts(systemd_coredump_t)
469472#
470473
471474allow systemd_generator_t self:fifo_file rw_fifo_file_perms;
472- allow systemd_generator_t self:capability dac_override;
475+ allow systemd_generator_t self:capability { dac_override sys_admin } ;
473476allow systemd_generator_t self:process setfscreate;
474477
475478corecmd_exec_shell(systemd_generator_t)
@@ -699,6 +702,7 @@ fs_getattr_all_fs(systemd_hostnamed_t)
699702
700703selinux_use_status_page(systemd_hostnamed_t)
701704
705+ seutil_read_config(systemd_hostnamed_t)
702706seutil_read_file_contexts(systemd_hostnamed_t)
703707
704708sysnet_etc_filetrans_config(systemd_hostnamed_t)
@@ -1391,8 +1395,7 @@ manage_dirs_pattern(systemd_rfkill_t, systemd_rfkill_var_lib_t, systemd_rfkill_v
13911395manage_files_pattern(systemd_rfkill_t, systemd_rfkill_var_lib_t, systemd_rfkill_var_lib_t)
13921396init_var_lib_filetrans(systemd_rfkill_t, systemd_rfkill_var_lib_t, dir)
13931397
1394- fs_getattr_cgroup(systemd_rfkill_t)
1395- fs_getattr_xattr_fs(systemd_rfkill_t)
1398+ fs_getattr_all_fs(systemd_rfkill_t)
13961399
13971400kernel_getattr_proc(systemd_rfkill_t)
13981401kernel_read_kernel_sysctls(systemd_rfkill_t)
0 commit comments