Revert "selinux: Drop user_namespace class rules for Fedora 37"

This reverts commit 3fb3f0f7a5: it was
meant as a patch for Fedora 37 (and no later versions), not something
I should have merged upstream.

Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
This commit is contained in:
Stefano Brivio 2023-11-07 14:58:02 +01:00
parent 74e6f48038
commit 56d9f6d588
2 changed files with 4 additions and 0 deletions

View file

@ -53,6 +53,7 @@ require {
class capability { sys_tty_config setuid setgid }; class capability { sys_tty_config setuid setgid };
class cap_userns { setpcap sys_admin sys_ptrace }; class cap_userns { setpcap sys_admin sys_ptrace };
class user_namespace create;
} }
type passt_t; type passt_t;
@ -92,6 +93,7 @@ allow syslogd_t self:cap_userns sys_ptrace;
allow passt_t self:process setcap; allow passt_t self:process setcap;
allow passt_t self:capability { sys_tty_config setpcap net_bind_service setuid setgid}; allow passt_t self:capability { sys_tty_config setpcap net_bind_service setuid setgid};
allow passt_t self:cap_userns { setpcap sys_admin sys_ptrace }; allow passt_t self:cap_userns { setpcap sys_admin sys_ptrace };
allow passt_t self:user_namespace create;
allow passt_t passwd_file_t:file read_file_perms; allow passt_t passwd_file_t:file read_file_perms;
sssd_search_lib(passt_t) sssd_search_lib(passt_t)

View file

@ -88,6 +88,7 @@ require {
class capability { sys_tty_config setuid setgid }; class capability { sys_tty_config setuid setgid };
class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin }; class cap_userns { setpcap sys_admin sys_ptrace net_bind_service net_admin };
class user_namespace create;
} }
type pasta_t; type pasta_t;
@ -112,6 +113,7 @@ init_daemon_domain(pasta_t, pasta_exec_t)
allow pasta_t self:capability { setpcap net_bind_service sys_tty_config dac_read_search net_admin sys_resource setuid setgid }; allow pasta_t self:capability { setpcap net_bind_service sys_tty_config dac_read_search net_admin sys_resource setuid setgid };
allow pasta_t self:cap_userns { setpcap sys_admin sys_ptrace net_admin net_bind_service }; allow pasta_t self:cap_userns { setpcap sys_admin sys_ptrace net_admin net_bind_service };
allow pasta_t self:user_namespace create;
allow pasta_t passwd_file_t:file read_file_perms; allow pasta_t passwd_file_t:file read_file_perms;
sssd_search_lib(pasta_t) sssd_search_lib(pasta_t)