2022-08-05 17:36:47 +08:00
|
|
|
diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in
|
2023-01-03 19:16:35 +08:00
|
|
|
index 9f51f604e..77b0bd98f 100644
|
2022-08-05 17:36:47 +08:00
|
|
|
--- a/selinux/openvswitch-custom.te.in
|
|
|
|
|
+++ b/selinux/openvswitch-custom.te.in
|
2023-01-03 19:16:35 +08:00
|
|
|
@@ -15,6 +15,7 @@ require {
|
2022-08-05 17:36:47 +08:00
|
|
|
type ifconfig_exec_t;
|
|
|
|
|
type init_t;
|
|
|
|
|
type init_var_run_t;
|
2023-01-03 19:16:35 +08:00
|
|
|
+ type initrc_t;
|
2022-08-05 17:36:47 +08:00
|
|
|
type insmod_exec_t;
|
|
|
|
|
type kernel_t;
|
|
|
|
|
type hostname_exec_t;
|
2023-01-03 19:16:35 +08:00
|
|
|
@@ -118,6 +119,7 @@ allow openvswitch_t openvswitch_load_module_t:process transition;
|
2022-08-05 17:36:47 +08:00
|
|
|
allow openvswitch_load_module_t bin_t:file { execute execute_no_trans map };
|
|
|
|
|
allow openvswitch_load_module_t init_t:unix_stream_socket { getattr ioctl read write };
|
|
|
|
|
allow openvswitch_load_module_t init_var_run_t:dir { getattr read open search };
|
|
|
|
|
+allow openvswitch_load_module_t initrc_t:fifo_file ioctl;
|
|
|
|
|
allow openvswitch_load_module_t insmod_exec_t:file { execute execute_no_trans getattr map open read };
|
|
|
|
|
allow openvswitch_load_module_t kernel_t:system module_request;
|
|
|
|
|
allow openvswitch_load_module_t modules_conf_t:dir { getattr open read search };
|