openvswitch/fix-selinux-err.patch

21 lines
1.0 KiB
Diff
Raw Normal View History

2022-08-05 17:36:47 +08:00
diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in
index 9f51f604e..77b0bd98f 100644
2022-08-05 17:36:47 +08:00
--- a/selinux/openvswitch-custom.te.in
+++ b/selinux/openvswitch-custom.te.in
@@ -15,6 +15,7 @@ require {
2022-08-05 17:36:47 +08:00
type ifconfig_exec_t;
type init_t;
type init_var_run_t;
+ type initrc_t;
2022-08-05 17:36:47 +08:00
type insmod_exec_t;
type kernel_t;
type hostname_exec_t;
@@ -118,6 +119,7 @@ allow openvswitch_t openvswitch_load_module_t:process transition;
2022-08-05 17:36:47 +08:00
allow openvswitch_load_module_t bin_t:file { execute execute_no_trans map };
allow openvswitch_load_module_t init_t:unix_stream_socket { getattr ioctl read write };
allow openvswitch_load_module_t init_var_run_t:dir { getattr read open search };
+allow openvswitch_load_module_t initrc_t:fifo_file ioctl;
allow openvswitch_load_module_t insmod_exec_t:file { execute execute_no_trans getattr map open read };
allow openvswitch_load_module_t kernel_t:system module_request;
allow openvswitch_load_module_t modules_conf_t:dir { getattr open read search };