Skip to content

Commit

Permalink
Merge branch 'bsc1231491' into 'factory'
Browse files Browse the repository at this point in the history
Fixes for SUSE specific slpd patches (bsc#1231491)

See merge request selinux/selinux-policy!114
  • Loading branch information
ca-hu committed Oct 18, 2024
2 parents ce2f393 + 35eeaeb commit 3f4b9dc
Showing 1 changed file with 7 additions and 0 deletions.
7 changes: 7 additions & 0 deletions policy/modules/contrib/slpd.te
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,13 @@ files_pid_file(slpd_var_run_t)
#

allow slpd_t self:capability { kill net_admin setgid setuid };

# SUSE specific patch "extensions.diff" in openslp needs chroot()
allow slpd_t self:capability sys_chroot;

# SUSE specific patch "openslp.netlink.diff" in openslp uses TCPDIAG_GETSOCK
allow slpd_t self:netlink_tcpdiag_socket create;

allow slpd_t self:process signal;
allow slpd_t self:fifo_file rw_fifo_file_perms;
allow slpd_t self:tcp_socket { accept listen };
Expand Down

0 comments on commit 3f4b9dc

Please sign in to comment.