selinux-policy/backport-Allow-dhcpc_t-domain-transition-to-chronyc_t.patch
2021-05-31 18:58:06 +08:00

31 lines
958 B
Diff

From 32aa3f5509900563632fec1a1536c84da50553ed Mon Sep 17 00:00:00 2001
From: Zdenek Pytela <zpytela@redhat.com>
Date: Thu, 1 Apr 2021 17:36:08 +0200
Reference: https://github.com/fedora-selinux/selinux-policy/commit/32aa3f5509900563632fec1a1536c84da50553ed
Conflict: NA
Subject: [PATCH] Allow dhcpc_t domain transition to chronyc_t
This permission is required when dhclient-script executes
the chrony.sh script from /etc/dhcp/dhclient.d.
Resolves: rhbz#1897388
---
policy/modules/system/sysnetwork.te | 1 +
1 file changed, 1 insertion(+)
diff --git a/policy/modules/system/sysnetwork.te b/policy/modules/system/sysnetwork.te
index fb0a0c8..70eaf92 100644
--- a/policy/modules/system/sysnetwork.te
+++ b/policy/modules/system/sysnetwork.te
@@ -198,6 +198,7 @@ optional_policy(`
chronyd_initrc_domtrans(dhcpc_t)
chronyd_systemctl(dhcpc_t)
chronyd_domtrans(dhcpc_t)
+ chronyd_domtrans_chronyc(dhcpc_t)
chronyd_read_keys(dhcpc_t)
')
--
1.8.3.1