diff --git a/init.te b/init.te index 5f0ccc7d15f863c762d0a8716d07673f4cadb661..676b7841033f353dfc0eacd89daba90a1f02828d 100644 --- a/init.te +++ b/init.te @@ -11,12 +11,16 @@ allow init tmpfs:chr_file create_file_perms; # # init direct restorecon calls. # -# /dev/socket -allow init { device socket_device }:dir relabelto; +# /dev/kmsg +allow init tmpfs:chr_file relabelfrom; +allow init kmsg_device:chr_file { write relabelto }; # /dev/__properties__ allow init properties_device:dir relabelto; allow init properties_serial:file { write relabelto }; allow init property_type:file { create_file_perms relabelto }; +# /dev/socket +allow init { device socket_device }:dir relabelto; + allow init kernel:fd use; # setrlimit