File tree Expand file tree Collapse file tree 4 files changed +13
-7
lines changed Expand file tree Collapse file tree 4 files changed +13
-7
lines changed Original file line number Diff line number Diff line change 1010/usr/lib/systemd/system/nfs.* -- gen_context(system_u:object_r:nfsd_unit_file_t,s0)
1111/usr/lib/systemd/system/rpc.* -- gen_context(system_u:object_r:rpcd_unit_file_t,s0)
1212
13- /usr/lib/systemd/system-generators/nfs.* -- gen_context(system_u:object_r:nfsd_exec_t,s0)
14-
1513#
1614# /usr
1715#
Original file line number Diff line number Diff line change @@ -295,11 +295,6 @@ fs_manage_nfsd_fs(nfsd_t)
295295storage_raw_read_fixed_disk(nfsd_t)
296296storage_raw_read_removable_device(nfsd_t)
297297
298- allow nfsd_t nfsd_unit_file_t:file manage_file_perms;
299- systemd_unit_file_filetrans(nfsd_t, nfsd_unit_file_t, file)
300- systemd_create_unit_file_dirs(nfsd_t)
301- systemd_create_unit_file_lnk(nfsd_t)
302-
303298# Read access to public_content_t and public_content_rw_t
304299miscfiles_read_public_files(nfsd_t)
305300
Original file line number Diff line number Diff line change @@ -81,6 +81,9 @@ HOME_DIR/\.config/systemd/user(/.*)? gen_context(system_u:object_r:systemd_unit
8181/usr/lib/systemd/systemd-network-generator -- gen_context(system_u:object_r:systemd_network_generator_exec_t,s0)
8282
8383/usr/lib/systemd/system-generators/bootc-systemd-generator -- gen_context(system_u:object_r:systemd_bootc_generator_exec_t,s0)
84+ /usr/lib/systemd/system-generators/nfsroot-generator -- gen_context(system_u:object_r:systemd_nfs_generator_exec_t,s0)
85+ /usr/lib/systemd/system-generators/nfs-server-generator -- gen_context(system_u:object_r:systemd_nfs_generator_exec_t,s0)
86+ /usr/lib/systemd/system-generators/rpc-pipefs-generator -- gen_context(system_u:object_r:systemd_nfs_generator_exec_t,s0)
8487/usr/lib/systemd/system-generators/systemd-bless-boot-generator -- gen_context(system_u:object_r:systemd_bless_boot_generator_exec_t,s0)
8588/usr/lib/systemd/system-generators/systemd-cryptsetup-generator -- gen_context(system_u:object_r:systemd_cryptsetup_generator_exec_t,s0)
8689/usr/lib/systemd/system-generators/systemd-debug-generator -- gen_context(system_u:object_r:systemd_debug_generator_exec_t,s0)
Original file line number Diff line number Diff line change @@ -220,6 +220,8 @@ systemd_generator_template(systemd_getty_generator)
220220systemd_generator_template(systemd_gpt_generator)
221221# import-generator
222222systemd_generator_template(systemd_import_generator)
223+ # nfs generator
224+ systemd_generator_template(systemd_nfs_generator)
223225# rc-local-generator
224226systemd_generator_template(systemd_rc_local_generator)
225227# ssh-generator
@@ -1466,6 +1468,14 @@ optional_policy(`
14661468 udev_read_pid_files(systemd_gpt_generator_t)
14671469')
14681470
1471+ # ## nfs generator
1472+ permissive systemd_nfs_generator_t;
1473+
1474+ # allow nfsd_t nfsd_unit_file_t:file manage_file_perms;
1475+ # systemd_unit_file_filetrans(nfsd_t, nfsd_unit_file_t, file)
1476+ # systemd_create_unit_file_dirs(nfsd_t)
1477+ # systemd_create_unit_file_lnk(nfsd_t)
1478+
14691479# ## systemd rc_local generator
14701480init_exec_script_files(systemd_rc_local_generator_t)
14711481
You can’t perform that action at this time.
0 commit comments