domtrans_pattern(init_t,$2,$1)
allow init_t $1:unix_stream_socket create_stream_socket_perms;
allow init_t $1:unix_dgram_socket create_socket_perms;
- allow $1 init_t:unix_stream_socket ioctl;
+ allow $1 init_t:unix_stream_socket ioctl;
allow $1 init_t:unix_dgram_socket sendto;
- # need write to /var/run/systemd/notify
- init_write_pid_socket($1)
+ # need write to /var/run/systemd/notify
+ init_write_pid_socket($1)
')
')
allow daemon init_t:unix_dgram_socket sendto;
# need write to /var/run/systemd/notify
init_write_pid_socket(daemon)
- dontaudit daemon init_t:unix_stream_socket { read ioctl getattr };
+ allow daemon init_t:unix_stream_socket { append write read getattr ioctl };
')
# daemons started from init will
allow init_t systemprocess:unix_stream_socket create_stream_socket_perms;
allow init_t systemprocess:unix_dgram_socket create_socket_perms;
allow systemprocess init_t:unix_dgram_socket sendto;
- dontaudit systemprocess init_t:unix_stream_socket { read getattr ioctl };
+ allow systemprocess init_t:unix_stream_socket { append write read getattr ioctl };
')
ifdef(`hide_broken_symptoms',`