Blame SOURCES/0057-extensions-SECMARK-Use-a-better-context-in-test-case.patch

926f74
From 2a45c01c4d3892871b3d3d6b67d10cb62abc561e Mon Sep 17 00:00:00 2001
926f74
From: Phil Sutter <psutter@redhat.com>
926f74
Date: Fri, 16 Jul 2021 21:51:49 +0200
926f74
Subject: [PATCH] extensions: SECMARK: Use a better context in test case
926f74
926f74
RHEL SELinux policies don't allow setting
926f74
system_u:object_r:firewalld_exec_t:s0 context. Use one instead which has
926f74
'packet_type' attribute (identified via
926f74
'seinfo -xt | grep packet_type').
926f74
---
926f74
 extensions/libxt_SECMARK.t | 2 +-
926f74
 1 file changed, 1 insertion(+), 1 deletion(-)
926f74
926f74
diff --git a/extensions/libxt_SECMARK.t b/extensions/libxt_SECMARK.t
926f74
index 39d4c09348bf4..295e7a7244902 100644
926f74
--- a/extensions/libxt_SECMARK.t
926f74
+++ b/extensions/libxt_SECMARK.t
926f74
@@ -1,4 +1,4 @@
926f74
 :INPUT,FORWARD,OUTPUT
926f74
 *security
926f74
--j SECMARK --selctx system_u:object_r:firewalld_exec_t:s0;=;OK
926f74
+-j SECMARK --selctx system_u:object_r:ssh_server_packet_t:s0;=;OK
926f74
 -j SECMARK;;FAIL
926f74
-- 
926f74
2.31.1
926f74