1 |
commit: ecf21a2dc57dd85fe6065a1bb2996a72daa6ca78 |
2 |
Author: Laurent Bigonville <bigon <AT> bigon <DOT> be> |
3 |
AuthorDate: Thu Nov 1 10:12:26 2018 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Nov 18 10:56:47 2018 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=ecf21a2d |
7 |
|
8 |
irqbalance now creates an abstract socket |
9 |
|
10 |
Signed-off-by: Jason Zaman <jason <AT> perfinion.com> |
11 |
|
12 |
policy/modules/services/irqbalance.te | 1 + |
13 |
1 file changed, 1 insertion(+) |
14 |
|
15 |
diff --git a/policy/modules/services/irqbalance.te b/policy/modules/services/irqbalance.te |
16 |
index a71058d8..ade99be0 100644 |
17 |
--- a/policy/modules/services/irqbalance.te |
18 |
+++ b/policy/modules/services/irqbalance.te |
19 |
@@ -28,6 +28,7 @@ allow irqbalance_t self:capability { setpcap }; |
20 |
dontaudit irqbalance_t self:capability sys_tty_config; |
21 |
allow irqbalance_t self:process { getcap getsched setcap signal_perms }; |
22 |
allow irqbalance_t self:udp_socket create_socket_perms; |
23 |
+allow irqbalance_t self:unix_stream_socket create_stream_socket_perms; |
24 |
|
25 |
manage_files_pattern(irqbalance_t, irqbalance_pid_t, irqbalance_pid_t) |
26 |
files_pid_filetrans(irqbalance_t, irqbalance_pid_t, file) |