Allow clatd to use local/unix datagram socket inherited from netd.
Addresses denials such as: avc: denied { read write } for pid=3142 comm="clatd" path="socket:[12029]" dev="sockfs" ino=12029 scontext=u:r:clatd:s0 tcontext=u:r:netd:s0 tclass=unix_dgram_socket Change-Id: I5111410870c71bbfaf6b5310d8f5fd8f10db4f20 Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
This commit is contained in:
parent
6fe899a0d1
commit
e42cebe6a0
1 changed files with 2 additions and 0 deletions
2
clatd.te
2
clatd.te
|
@ -7,11 +7,13 @@ net_domain(clatd)
|
||||||
# Access objects inherited from netd.
|
# Access objects inherited from netd.
|
||||||
allow clatd netd:fd use;
|
allow clatd netd:fd use;
|
||||||
allow clatd netd:fifo_file { read write };
|
allow clatd netd:fifo_file { read write };
|
||||||
|
# TODO: Check whether some or all of these sockets should be close-on-exec.
|
||||||
allow clatd netd:netlink_kobject_uevent_socket { read write };
|
allow clatd netd:netlink_kobject_uevent_socket { read write };
|
||||||
allow clatd netd:netlink_nflog_socket { read write };
|
allow clatd netd:netlink_nflog_socket { read write };
|
||||||
allow clatd netd:netlink_route_socket { read write };
|
allow clatd netd:netlink_route_socket { read write };
|
||||||
allow clatd netd:udp_socket { read write };
|
allow clatd netd:udp_socket { read write };
|
||||||
allow clatd netd:unix_stream_socket { read write };
|
allow clatd netd:unix_stream_socket { read write };
|
||||||
|
allow clatd netd:unix_dgram_socket { read write };
|
||||||
|
|
||||||
allow clatd self:capability { net_admin setuid setgid };
|
allow clatd self:capability { net_admin setuid setgid };
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue