fedora-selinux / selinux-policy-contrib

Fedora Policy Contributions
39 stars 66 forks source link

Allow ptp4l_t sys_admin capability to run bpf programs #254

Closed zpytela closed 4 years ago

zpytela commented 4 years ago

In ptp4l, setsockopt() with SO_ATTACH_FILTER raises sk_attach_filter() running a bpf program, for which the SYS_ADMIN capability is required.

wrabcak commented 4 years ago

LGTM.