selinux-policy/fix_irqbalance.patch
Johannes Segitz f46ad9aabe Accepting request 1039192 from home:fbonazzi:branches:security:SELinux
- Add fix_irqbalance.patch: support netlink socket operations (bsc#1205434)
- Drop fix_irqbalance.patch: superseded by upstream

OBS-URL: https://build.opensuse.org/request/show/1039192
OBS-URL: https://build.opensuse.org/package/show/security:SELinux/selinux-policy?expand=0&rev=159
2022-12-01 07:07:05 +00:00

14 lines
812 B
Diff

Index: fedora-policy-20221019/policy/modules/contrib/irqbalance.te
===================================================================
--- fedora-policy-20221019.orig/policy/modules/contrib/irqbalance.te
+++ fedora-policy-20221019/policy/modules/contrib/irqbalance.te
@@ -24,7 +24,7 @@ files_pid_file(irqbalance_var_run_t)
allow irqbalance_t self:capability { setpcap net_admin };
dontaudit irqbalance_t self:capability sys_tty_config;
allow irqbalance_t self:process { getcap getsched setcap signal_perms };
-allow irqbalance_t self:udp_socket create_socket_perms;
+allow irqbalance_t self:{udp_socket netlink_generic_socket} create_socket_perms;
manage_dirs_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)
manage_files_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)