diff --git a/selinux/osbuild.te b/selinux/osbuild.te index 0851f324..1a5f98d4 100644 --- a/selinux/osbuild.te +++ b/selinux/osbuild.te @@ -51,6 +51,15 @@ optional_policy(` osbuild_run(unconfined_t, unconfined_r) ') +optional_policy(` + gen_require(` + type unconfined_service_t; + role system_r; + ') + + osbuild_run(unconfined_service_t, system_r) +') + # allow transitioning to install_t (for ostree) optional_policy(` anaconda_domtrans_install(osbuild_t)