diff --git a/src/selinux/swtpm_svirt.te b/src/selinux/swtpm_svirt.te index 75a25cf..5c255e9 100644 --- a/src/selinux/swtpm_svirt.te +++ b/src/selinux/swtpm_svirt.te @@ -4,12 +4,16 @@ require { type svirt_t; type swtpm_exec_t; type virtd_t; + type user_tmp_t; class file { entrypoint }; class process sigchld; class fifo_file write; + class sock_file { create setattr }; } #============= svirt_t ============== allow svirt_t virtd_t:fifo_file write; allow svirt_t virtd_t:process sigchld; +allow svirt_t user_tmp_t:sock_file { create setattr }; +allow svirt_t swtpm_exec_t:file entrypoint; \ No newline at end of file