selinux-policy/Add-permission-open-to-files_read_inherited_tmp_file.patch

30 lines
932 B
Diff

From 9c55448c7d59ea537fe8ee9e89b6196a6562ef5f Mon Sep 17 00:00:00 2001
From: luhuaxin <luhuaxin1@huawei.com>
Date: Thu, 28 Apr 2022 17:10:37 +0800
Subject: [PATCH] Add permission open to files_read_inherited_tmp_file
The open permission is deleted from upstream. We add it for
compatibility with historical release versions.
Signed-off-by: luhuaxin <luhuaxin1@huawei.com>
---
policy/modules/kernel/files.if | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if
index bca6f15..498c252 100644
--- a/policy/modules/kernel/files.if
+++ b/policy/modules/kernel/files.if
@@ -6428,7 +6428,7 @@ interface(`files_read_inherited_tmp_files',`
attribute tmpfile;
')
- allow $1 tmpfile:file { append read_inherited_file_perms };
+ allow $1 tmpfile:file { append open read_inherited_file_perms };
')
########################################
--
1.8.3.1