Skip to content

Commit aaa7ae7

Browse files
committed
Allow nfs-generator create and use udp sockets
The commit addresses the following AVC denial: type=AVC msg=audit(1756192855.476:472): avc: denied { create } for pid=2848 comm="nfs-server-gene" scontext=system_u:system_r:systemd_nfs_generator_t:s0 tcontext=system_u:system_r:systemd_nfs_generator_t:s0 tclass=udp_socket permissive=0 Resolves: RHEL-111556
1 parent 2f424aa commit aaa7ae7

File tree

1 file changed

+1
-5
lines changed

1 file changed

+1
-5
lines changed

policy/modules/system/systemd.te

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1495,11 +1495,7 @@ optional_policy(`
14951495

14961496
### nfs generator
14971497
permissive systemd_nfs_generator_t;
1498-
1499-
#allow nfsd_t nfsd_unit_file_t:file manage_file_perms;
1500-
#systemd_unit_file_filetrans(nfsd_t, nfsd_unit_file_t, file)
1501-
#systemd_create_unit_file_dirs(nfsd_t)
1502-
#systemd_create_unit_file_lnk(nfsd_t)
1498+
allow systemd_nfs_generator_t self:udp_socket create_socket_perms;
15031499

15041500
### systemd rc_local generator
15051501
init_exec_script_files(systemd_rc_local_generator_t)

0 commit comments

Comments
 (0)