@@ -29,10 +29,12 @@ files_runtime_file(tuned_runtime_t)
2929# Local policy
3030#
3131
32- allow tuned_t self:capability { sys_admin sys_nice };
32+ allow tuned_t self:capability { sys_admin sys_nice sys_ptrace };
3333dontaudit tuned_t self:capability { dac_override sys_tty_config };
34+ allow tuned_t self:cap_userns sys_ptrace;
3435allow tuned_t self:process { setsched signal };
3536allow tuned_t self:fifo_file rw_fifo_file_perms;
37+ allow tuned_t self:netlink_kobject_uevent_socket create_socket_perms;
3638
3739read_files_pattern(tuned_t, tuned_etc_t, tuned_etc_t)
3840exec_files_pattern(tuned_t, tuned_etc_t, tuned_etc_t)
@@ -50,12 +52,16 @@ manage_files_pattern(tuned_t, tuned_runtime_t, tuned_runtime_t)
5052manage_dirs_pattern(tuned_t, tuned_runtime_t, tuned_runtime_t)
5153files_runtime_filetrans(tuned_t, tuned_runtime_t, { dir file })
5254
55+ kernel_getattr_proc(tuned_t)
5356kernel_read_system_state(tuned_t)
5457kernel_read_network_state(tuned_t)
5558kernel_read_kernel_sysctls(tuned_t)
5659kernel_request_load_module(tuned_t)
60+ kernel_rw_fs_sysctls(tuned_t)
5761kernel_rw_kernel_sysctl(tuned_t)
5862kernel_rw_hotplug_sysctls(tuned_t)
63+ kernel_rw_net_sysctls(tuned_t)
64+ kernel_rw_vm_overcommit_sysctl(tuned_t)
5965kernel_rw_vm_sysctls(tuned_t)
6066
6167corecmd_exec_bin(tuned_t)
@@ -67,20 +73,43 @@ dev_read_urand(tuned_t)
6773dev_rw_sysfs(tuned_t)
6874dev_rw_pmqos(tuned_t)
6975
76+ # enumerate all running processes
77+ domain_read_all_domains_state(tuned_t)
78+
7079files_read_usr_files(tuned_t)
7180files_dontaudit_search_home(tuned_t)
7281files_dontaudit_list_tmp(tuned_t)
7382
7483fs_getattr_xattr_fs(tuned_t)
7584
85+ selinux_get_fs_mount(tuned_t)
86+ # set SELinux cache_threshold
87+ selinux_set_parameters(tuned_t)
88+
89+ auth_use_nsswitch(tuned_t)
90+
91+ libs_exec_ldconfig(tuned_t)
92+
7693logging_send_syslog_msg(tuned_t)
7794
95+ miscfiles_read_generic_certs(tuned_t)
7896miscfiles_read_localization(tuned_t)
7997
98+ seutil_dontaudit_search_config(tuned_t)
99+
80100udev_read_runtime_files(tuned_t)
81101
82102userdom_dontaudit_search_user_home_dirs(tuned_t)
83103
104+ ifdef(`init_systemd',`
105+ init_get_system_status(tuned_t)
106+ ')
107+
108+ optional_policy(`
109+ dbus_system_bus_client(tuned_t)
110+ dbus_connect_system_bus(tuned_t)
111+ ')
112+
84113optional_policy(`
85114 fstools_domtrans(tuned_t)
86115')
0 commit comments