diff --git a/selinux/openvswitch-custom.te.in b/selinux/openvswitch-custom.te.in index 9f51f604e..77b0bd98f 100644 --- a/selinux/openvswitch-custom.te.in +++ b/selinux/openvswitch-custom.te.in @@ -15,6 +15,7 @@ require { type ifconfig_exec_t; type init_t; type init_var_run_t; + type initrc_t; type insmod_exec_t; type kernel_t; type hostname_exec_t; @@ -118,6 +119,7 @@ allow openvswitch_t openvswitch_load_module_t:process transition; allow openvswitch_load_module_t bin_t:file { execute execute_no_trans map }; allow openvswitch_load_module_t init_t:unix_stream_socket { getattr ioctl read write }; allow openvswitch_load_module_t init_var_run_t:dir { getattr read open search }; +allow openvswitch_load_module_t initrc_t:fifo_file ioctl; allow openvswitch_load_module_t insmod_exec_t:file { execute execute_no_trans getattr map open read }; allow openvswitch_load_module_t kernel_t:system module_request; allow openvswitch_load_module_t modules_conf_t:dir { getattr open read search };