We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent a6a1608 commit 252c692Copy full SHA for 252c692
policy/modules/contrib/virt.te
@@ -2113,7 +2113,7 @@ allow virtqemud_t self:cap_userns kill;
2113
allow virtqemud_t self:netlink_audit_socket { nlmsg_relay read write };
2114
allow virtqemud_t self:process { setcap setexec setrlimit setsched setsockcreate };
2115
allow virtqemud_t self:tcp_socket create_socket_perms;
2116
-allow virtqemud_t self:tun_socket create;
+allow virtqemud_t self:tun_socket { create relabelfrom relabelto };
2117
allow virtqemud_t self:udp_socket { connect create getattr };
2118
2119
allow virtqemud_t qemu_var_run_t:{ dir file sock_file } relabelfrom;
0 commit comments