From e42cebe6a068a5273d4d022d27216d0d3cc62317 Mon Sep 17 00:00:00 2001
From: Stephen Smalley <sds@tycho.nsa.gov>
Date: Fri, 14 Mar 2014 08:22:19 -0400
Subject: [PATCH] Allow clatd to use local/unix datagram socket inherited from
 netd.

Addresses denials such as:
avc:  denied  { read write } for  pid=3142 comm="clatd" path="socket:[12029]" dev="sockfs" ino=12029 scontext=u:r:clatd:s0 tcontext=u:r:netd:s0 tclass=unix_dgram_socket

Change-Id: I5111410870c71bbfaf6b5310d8f5fd8f10db4f20
Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
---
 clatd.te | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/clatd.te b/clatd.te
index be0314df4..b1bda1e76 100644
--- a/clatd.te
+++ b/clatd.te
@@ -7,11 +7,13 @@ net_domain(clatd)
 # Access objects inherited from netd.
 allow clatd netd:fd use;
 allow clatd netd:fifo_file { read write };
+# TODO: Check whether some or all of these sockets should be close-on-exec.
 allow clatd netd:netlink_kobject_uevent_socket { read write };
 allow clatd netd:netlink_nflog_socket { read write };
 allow clatd netd:netlink_route_socket { read write };
 allow clatd netd:udp_socket { read write };
 allow clatd netd:unix_stream_socket { read write };
+allow clatd netd:unix_dgram_socket { read write };
 
 allow clatd self:capability { net_admin setuid setgid };
 
-- 
GitLab