Skip to content
Snippets Groups Projects
Commit 73b0346a authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Explictly allow init and kernel unlabeled access.


These permissions are already allowed indirectly via unconfineddomain
and via domain, but ultimately we plan to remove them from those two
attributes.  Explicitly allow the ones we expect to be required,
matching the complement of the auditallow rules in domain.te.

Change-Id: I43edca89d59c159b97d49932239f8952a848031c
Signed-off-by: default avatarStephen Smalley <sds@tycho.nsa.gov>
parent f85c1fc2
No related branches found
No related tags found
Loading
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment