Index: fedora-policy-20221019/policy/modules/system/systemd.te =================================================================== --- fedora-policy-20221019.orig/policy/modules/system/systemd.te +++ fedora-policy-20221019/policy/modules/system/systemd.te @@ -381,6 +381,10 @@ userdom_manage_user_tmp_chr_files(system xserver_dbus_chat(systemd_logind_t) optional_policy(` + packagekit_dbus_chat(systemd_logind_t) +') + +optional_policy(` apache_read_tmp_files(systemd_logind_t) ') @@ -863,6 +867,10 @@ optional_policy(` dbus_system_bus_client(systemd_localed_t) ') +optional_policy(` + nscd_unconfined(systemd_hostnamed_t) +') + ####################################### # # Hostnamed policy @@ -1158,7 +1166,7 @@ systemd_read_efivarfs(systemd_hwdb_t) # systemd_gpt_generator domain # -allow systemd_gpt_generator_t self:capability sys_rawio; +allow systemd_gpt_generator_t self:capability { sys_rawio sys_admin}; allow systemd_gpt_generator_t self:netlink_kobject_uevent_socket create_socket_perms; dev_read_sysfs(systemd_gpt_generator_t) @@ -1185,6 +1193,8 @@ systemd_unit_file_filetrans(systemd_gpt_ systemd_create_unit_file_dirs(systemd_gpt_generator_t) systemd_create_unit_file_lnk(systemd_gpt_generator_t) +kernel_dgram_send(systemd_gpt_generator_t) + optional_policy(` udev_read_pid_files(systemd_gpt_generator_t) ')