diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index ee97ad20fa..8d4f2b9afc 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -600,7 +600,9 @@ optional_policy(` # systemd-networkd local policy # +allow systemd_networkd_t self:bpf { map_create map_read map_write prog_load prog_run }; allow systemd_networkd_t self:capability { dac_read_search dac_override net_admin net_raw setuid fowner chown setgid setpcap }; +allow systemd_networkd_t self:capability2 bpf; allow systemd_networkd_t self:process { getcap setcap }; allow systemd_networkd_t self:netlink_kobject_uevent_socket create_socket_perms;