2021-10-29 21:13:23

by Kenton Groombridge

[permalink] [raw]
Subject: [PATCH 7/7] corenet: make netlabel_peer_t mcs constrained

Signed-off-by: Kenton Groombridge <[email protected]>
---
policy/modules/kernel/corenetwork.te.in | 1 +
1 file changed, 1 insertion(+)

diff --git a/policy/modules/kernel/corenetwork.te.in b/policy/modules/kernel/corenetwork.te.in
index 010fc808e..42bbfc8df 100644
--- a/policy/modules/kernel/corenetwork.te.in
+++ b/policy/modules/kernel/corenetwork.te.in
@@ -53,6 +53,7 @@ network_packet_simple(icmp)
#
type netlabel_peer_t;
sid netmsg gen_context(system_u:object_r:netlabel_peer_t,mls_systemhigh)
+mcs_constrained(netlabel_peer_t)

#
# port_t is the default type of INET port numbers.
--
2.33.1