2020-03-05 11:13:59 +01:00
|
|
|
Index: fedora-policy/policy/modules/contrib/irqbalance.te
|
|
|
|
===================================================================
|
2020-03-17 15:46:20 +01:00
|
|
|
--- fedora-policy.orig/policy/modules/contrib/irqbalance.te
|
|
|
|
+++ fedora-policy/policy/modules/contrib/irqbalance.te
|
|
|
|
@@ -25,8 +25,12 @@ dontaudit irqbalance_t self:capability s
|
|
|
|
allow irqbalance_t self:process { getcap getsched setcap signal_perms };
|
|
|
|
allow irqbalance_t self:udp_socket create_socket_perms;
|
2020-03-05 11:13:59 +01:00
|
|
|
|
2020-03-17 15:46:20 +01:00
|
|
|
+manage_dirs_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)
|
|
|
|
manage_files_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)
|
|
|
|
-files_pid_filetrans(irqbalance_t, irqbalance_var_run_t, file)
|
|
|
|
+manage_sock_files_pattern(irqbalance_t, irqbalance_var_run_t, irqbalance_var_run_t)
|
|
|
|
+files_pid_filetrans(irqbalance_t, irqbalance_var_run_t, { dir file sock_file })
|
2020-03-05 11:13:59 +01:00
|
|
|
+
|
2020-03-17 15:46:20 +01:00
|
|
|
+init_nnp_daemon_domain(irqbalance_t)
|
|
|
|
|
2020-03-05 11:13:59 +01:00
|
|
|
kernel_read_network_state(irqbalance_t)
|
|
|
|
kernel_read_system_state(irqbalance_t)
|