From Debian package 0.0.20080702-4 Allow initrc_t to control adjtime Allow initrc to manage initrc_var_run_t Index: policy/modules/system/init.te =================================================================== --- policy/modules/system/init.te.orig +++ policy/modules/system/init.te @@ -294,6 +294,7 @@ dev_read_framebuffer(initrc_t) dev_write_framebuffer(initrc_t) dev_read_realtime_clock(initrc_t) +clock_rw_adjtime(initrc_t) dev_read_sound_mixer(initrc_t) dev_write_sound_mixer(initrc_t) dev_setattr_all_chr_files(initrc_t) @@ -425,6 +426,8 @@ # for /etc/network/run/ifstate sysnet_manage_config(initrc_t) fs_tmpfs_filetrans(initrc_t, initrc_var_run_t, dir) + allow initrc_t initrc_var_run_t:dir manage_dir_perms; + allow initrc_t initrc_var_run_t:lnk_file manage_lnk_file_perms; # for storing state under /dev/shm fs_setattr_tmpfs_dirs(initrc_t)