Skip to content

Commit

Permalink
Label /run/sssd with sssd_var_run_t
Browse files Browse the repository at this point in the history
Additionally, allow sssd map sssd_var_run_t files.

Resolves: RHEL-57065
  • Loading branch information
zpytela committed Oct 22, 2024
1 parent e5a216a commit b108072
Show file tree
Hide file tree
Showing 2 changed files with 2 additions and 0 deletions.
1 change: 1 addition & 0 deletions policy/modules/contrib/sssd.fc
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@

/var/log/sssd(/.*)? gen_context(system_u:object_r:sssd_var_log_t,s0)

/run/sssd(/.*)? gen_context(system_u:object_r:sssd_var_run_t,s0)
/run/sssd.pid -- gen_context(system_u:object_r:sssd_var_run_t,s0)
/run/secrets\.socket -s gen_context(system_u:object_r:sssd_var_run_t,s0)
/run/\.heim_org\.h5l\.kcm-socket -s gen_context(system_u:object_r:sssd_var_run_t,s0)
1 change: 1 addition & 0 deletions policy/modules/contrib/sssd.te
Original file line number Diff line number Diff line change
Expand Up @@ -101,6 +101,7 @@ manage_dirs_pattern(sssd_t, sssd_var_run_t, sssd_var_run_t)
manage_files_pattern(sssd_t, sssd_var_run_t, sssd_var_run_t)
manage_sock_files_pattern(sssd_t, sssd_var_run_t, sssd_var_run_t)
files_pid_filetrans(sssd_t, sssd_var_run_t, { file dir sock_file })
allow sssd_t sssd_var_run_t:file map;

kernel_io_uring_use(sssd_t)
kernel_read_network_state(sssd_t)
Expand Down

0 comments on commit b108072

Please sign in to comment.