selinux-policy/backport-Allow-ftpd-map-ftpd_var_run-files.patch

23 lines
944 B
Diff

From 58294166420c372e9788b9c0308b1240dbad0c60 Mon Sep 17 00:00:00 2001
From: Nikola Knazekova <nknazeko@redhat.com>
Date: Thu, 6 Oct 2022 18:30:58 +0200
Subject: [PATCH] Allow ftpd map ftpd_var_run files
Resolves: bz#2124943
---
policy/modules/contrib/ftp.te | 1 +
1 file changed, 1 insertion(+)
diff --git a/policy/modules/contrib/ftp.te b/policy/modules/contrib/ftp.te
index ad80f16496..5edd00839f 100644
--- a/policy/modules/contrib/ftp.te
+++ b/policy/modules/contrib/ftp.te
@@ -161,6 +161,7 @@ manage_fifo_files_pattern(ftpd_t, ftpd_tmpfs_t, ftpd_tmpfs_t)
manage_sock_files_pattern(ftpd_t, ftpd_tmpfs_t, ftpd_tmpfs_t)
fs_tmpfs_filetrans(ftpd_t, ftpd_tmpfs_t, { dir file lnk_file sock_file fifo_file })
+allow ftpd_t ftpd_var_run_t:file map;
manage_dirs_pattern(ftpd_t, ftpd_var_run_t, ftpd_var_run_t)
manage_files_pattern(ftpd_t, ftpd_var_run_t, ftpd_var_run_t)
manage_sock_files_pattern(ftpd_t, ftpd_var_run_t, ftpd_var_run_t)