From 173aae2fb123f85237be5a452107104c323165f5 Mon Sep 17 00:00:00 2001 From: SamarV-121 Date: Wed, 14 Sep 2022 22:56:58 +0530 Subject: [PATCH] sepolicy: bsp: non_plat: Grant all network permissions to ipsec_mon Change-Id: I01ffcf9cc31332f45f9a1d3120c6d2946d3dc650 --- bsp/non_plat/ipsec_mon.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/bsp/non_plat/ipsec_mon.te b/bsp/non_plat/ipsec_mon.te index 363b5ec..812d531 100644 --- a/bsp/non_plat/ipsec_mon.te +++ b/bsp/non_plat/ipsec_mon.te @@ -9,6 +9,8 @@ type ipsec_mon_exec, exec_type, file_type, vendor_file_type; init_daemon_domain(ipsec_mon) +net_domain(ipsec_mon) + allow ipsec_mon self:netlink_xfrm_socket { write bind create read nlmsg_read nlmsg_write}; allow ipsec_mon ims_ipsec_data_file:dir w_dir_perms; allow ipsec_mon ims_ipsec_data_file:file create_file_perms;