From d677f3d6231d352fdb65b70f67d85fb5744e912c Mon Sep 17 00:00:00 2001 From: Marius Bakke Date: Thu, 10 Dec 2020 23:42:48 +0100 Subject: [PATCH] etc: Add more SELinux permissions for the daemon. * etc/guix-daemon.cil.in (guix_daemon): Permit file write, getattr, link and unlink for the guix_daemon_exec_t type. --- etc/guix-daemon.cil.in | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/etc/guix-daemon.cil.in b/etc/guix-daemon.cil.in index cc8999d9a8..4f52157354 100644 --- a/etc/guix-daemon.cil.in +++ b/etc/guix-daemon.cil.in @@ -167,7 +167,9 @@ (process (fork execmem setrlimit setpgid setsched))) (allow guix_daemon_t guix_daemon_exec_t - (file (execute execute_no_trans read open entrypoint map))) + (file (execute + execute_no_trans read write open entrypoint map + getattr link unlink))) ;; TODO: unknown (allow guix_daemon_t -- 2.20.1