Blame SOURCES/policy-rhel-7.7.z-contrib.patch

f939a2
diff --git a/sbd.te b/sbd.te
f939a2
index 0ba6d491f..927cb8f64 100644
f939a2
--- a/sbd.te
f939a2
+++ b/sbd.te
f939a2
@@ -37,6 +37,8 @@ manage_files_pattern(sbd_t, sbd_tmpfs_t, sbd_tmpfs_t)
f939a2
 manage_dirs_pattern(sbd_t, sbd_tmpfs_t, sbd_tmpfs_t)
f939a2
 fs_tmpfs_filetrans(sbd_t, sbd_tmpfs_t, { file dir })
f939a2
 
f939a2
+auth_use_nsswitch(sbd_t)
f939a2
+
f939a2
 kernel_read_system_state(sbd_t)
f939a2
 kernel_dgram_send(sbd_t)
f939a2
 kernel_rw_all_sysctls(sbd_t)
7d8214
diff --git a/tmpreaper.te b/tmpreaper.te
7d8214
index a00757adc..0aca5b5fb 100644
7d8214
--- a/tmpreaper.te
7d8214
+++ b/tmpreaper.te
7d8214
@@ -40,18 +40,27 @@ init_nnp_daemon_domain(tmpreaper_t)
7d8214
 # Local Policy
7d8214
 #
7d8214
 
7d8214
-allow tmpreaper_t self:capability { dac_override dac_read_search fowner };
7d8214
+allow tmpreaper_t self:capability { dac_override dac_read_search fowner sys_ptrace };
7d8214
 allow tmpreaper_t self:fifo_file rw_fifo_file_perms;
7d8214
 
7d8214
 kernel_list_unlabeled(tmpreaper_t)
7d8214
 kernel_read_system_state(tmpreaper_t)
7d8214
+kernel_read_network_state(tmpreaper_t)
7d8214
 kernel_delete_unlabeled(tmpreaper_t)
7d8214
+kernel_dontaudit_getattr_all_sysctls(tmpreaper_t)
7d8214
 
7d8214
 dev_read_urand(tmpreaper_t)
7d8214
+dev_getattr_all_chr_files(tmpreaper_t)
7d8214
+dev_getattr_all_blk_files(tmpreaper_t)
7d8214
+dev_getattr_mtrr_dev(tmpreaper_t)
7d8214
 
7d8214
 corecmd_exec_bin(tmpreaper_t)
7d8214
 corecmd_exec_shell(tmpreaper_t)
7d8214
 
7d8214
+domain_read_all_domains_state(tmpreaper_t)
7d8214
+domain_getattr_all_sockets(tmpreaper_t)
7d8214
+domain_getattr_all_pipes(tmpreaper_t)
7d8214
+
7d8214
 fs_getattr_xattr_fs(tmpreaper_t)
7d8214
 fs_list_all(tmpreaper_t)
7d8214
 fs_setattr_tmpfs_dirs(tmpreaper_t)