Skip to content

Commit f6c4144

Browse files
authored
Merge pull request #857 from yizhao1/fix
systemd fixes
2 parents 265d949 + e0477ab commit f6c4144

File tree

2 files changed

+6
-0
lines changed

2 files changed

+6
-0
lines changed

policy/modules/services/ntp.te

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -157,6 +157,7 @@ ifdef(`init_systemd',`
157157
allow ntpd_t self:capability { fowner setpcap };
158158
init_read_state(ntpd_t)
159159
init_reload(ntpd_t)
160+
init_watch_runtime_dirs(ntpd_t)
160161
fs_watch_memory_pressure(ntpd_t)
161162

162163
# for /var/lib/systemd/clock

policy/modules/system/systemd.te

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1760,12 +1760,14 @@ files_watch_runtime_dirs(systemd_resolved_t)
17601760
files_list_runtime(systemd_resolved_t)
17611761

17621762
fs_getattr_all_fs(systemd_resolved_t)
1763+
fs_getattr_nsfs_files(systemd_resolved_t)
17631764
fs_search_cgroup_dirs(systemd_resolved_t)
17641765
fs_search_tmpfs(systemd_resolved_t)
17651766
fs_search_ramfs(systemd_resolved_t)
17661767
fs_watch_memory_pressure(systemd_resolved_t)
17671768

17681769
init_dgram_send(systemd_resolved_t)
1770+
init_watch_runtime_dirs(systemd_resolved_t)
17691771

17701772
miscfiles_read_generic_certs(systemd_resolved_t)
17711773

@@ -1873,6 +1875,7 @@ allow systemd_sysusers_t self:unix_dgram_socket sendto;
18731875
files_manage_etc_files(systemd_sysusers_t)
18741876

18751877
fs_getattr_all_fs(systemd_sysusers_t)
1878+
fs_getattr_nsfs_files(systemd_sysusers_t)
18761879
fs_search_all(systemd_sysusers_t)
18771880

18781881
kernel_read_kernel_sysctls(systemd_sysusers_t)
@@ -2065,6 +2068,7 @@ files_etc_filetrans(systemd_update_done_t, systemd_update_run_t, file)
20652068
files_var_filetrans(systemd_update_done_t, systemd_update_run_t, file)
20662069

20672070
fs_getattr_all_fs(systemd_update_done_t)
2071+
fs_getattr_nsfs_files(systemd_update_done_t)
20682072
fs_search_cgroup_dirs(systemd_update_done_t)
20692073

20702074
kernel_read_kernel_sysctls(systemd_update_done_t)
@@ -2181,6 +2185,7 @@ files_read_etc_runtime_files(systemd_userdbd_t)
21812185
files_read_usr_files(systemd_userdbd_t)
21822186

21832187
fs_getattr_all_fs(systemd_userdbd_t)
2188+
fs_getattr_nsfs_files(systemd_userdbd_t)
21842189
fs_search_cgroup_dirs(systemd_userdbd_t)
21852190
fs_read_efivarfs_files(systemd_userdbd_t)
21862191
fs_watch_memory_pressure(systemd_userdbd_t)

0 commit comments

Comments
 (0)