Add missing map permission for gunicorn under selinux
Resolves an AVC when gunicorn attempts to use the python3 interpreter from the virtualenv. Change-Id: I0be8ebb0bad407e6f9aa9703db0d2a61026c87cd
This commit is contained in:
parent
09ba06020d
commit
81c70774c8
|
@ -4,11 +4,11 @@ require {
|
|||
type var_lib_t;
|
||||
type postgresql_db_t;
|
||||
type init_t;
|
||||
class file { execute execute_no_trans getattr open read };
|
||||
class file { execute execute_no_trans getattr open read map };
|
||||
class lnk_file { getattr read };
|
||||
}
|
||||
|
||||
#============= init_t ==============
|
||||
allow init_t postgresql_db_t:file { getattr open read };
|
||||
allow init_t var_lib_t:file { execute execute_no_trans };
|
||||
allow init_t var_lib_t:file { execute execute_no_trans map };
|
||||
allow init_t var_lib_t:lnk_file { getattr read };
|
||||
|
|
Loading…
Reference in New Issue