File tree Expand file tree Collapse file tree 2 files changed +6
-0
lines changed Expand file tree Collapse file tree 2 files changed +6
-0
lines changed Original file line number Diff line number Diff line change @@ -21,6 +21,9 @@ gen_tunable(staff_use_svirt, false)
2121#
2222# Local policy
2323#
24+
25+ allow staff_t self:system all_system_perms;
26+
2427corenet_ib_access_unlabeled_pkeys(staff_t)
2528
2629kernel_read_ring_buffer(staff_t)
@@ -255,6 +258,7 @@ optional_policy(`
255258
256259optional_policy(`
257260 systemd_read_unit_files(staff_t)
261+ systemd_config_all_services(staff_t)
258262 systemd_exec_systemctl(staff_t)
259263')
260264
Original file line number Diff line number Diff line change @@ -10,6 +10,8 @@ role sysadm_r;
1010userdom_admin_user_template(sysadm)
1111allow sysadm_t self:netlink_tcpdiag_socket create_netlink_socket_perms;
1212
13+ allow sysadm_t self:system all_system_perms;
14+
1315
1416# #######################################
1517#
You can’t perform that action at this time.
0 commit comments