Merge "selinux - remove clatd tun creation privs"
This commit is contained in:
commit
fbae4d9b35
1 changed files with 2 additions and 3 deletions
|
@ -32,6 +32,5 @@ allow clatd self:global_capability_class_set { net_admin net_raw setuid setgid }
|
||||||
allow clatd self:global_capability_class_set ipc_lock;
|
allow clatd self:global_capability_class_set ipc_lock;
|
||||||
|
|
||||||
allow clatd self:netlink_route_socket nlmsg_write;
|
allow clatd self:netlink_route_socket nlmsg_write;
|
||||||
allow clatd self:{ packet_socket rawip_socket tun_socket } create_socket_perms_no_ioctl;
|
allow clatd self:{ packet_socket rawip_socket } create_socket_perms_no_ioctl;
|
||||||
allow clatd tun_device:chr_file rw_file_perms;
|
allow clatd tun_device:chr_file rw_file_perms;
|
||||||
allowxperm clatd tun_device:chr_file ioctl { TUNGETIFF TUNSETIFF };
|
|
Loading…
Reference in a new issue