diff --git a/policy-rawhide-base.patch b/policy-rawhide-base.patch index 8da2c4cb..8fa866d4 100644 --- a/policy-rawhide-base.patch +++ b/policy-rawhide-base.patch @@ -28892,7 +28892,7 @@ index fe0c682..60003bc 100644 + ps_process_pattern($1, sshd_t) +') diff --git a/policy/modules/services/ssh.te b/policy/modules/services/ssh.te -index cc877c7..80996f3 100644 +index cc877c7..4d56aea 100644 --- a/policy/modules/services/ssh.te +++ b/policy/modules/services/ssh.te @@ -6,43 +6,69 @@ policy_module(ssh, 2.4.2) @@ -29004,7 +29004,7 @@ index cc877c7..80996f3 100644 # -allow ssh_t self:capability { setuid setgid dac_override dac_read_search }; -+allow ssh_t self:capability { setcap setuid setgid dac_override dac_read_search }; ++allow ssh_t self:capability { setpcap setuid setgid dac_override dac_read_search }; allow ssh_t self:process ~{ ptrace setcurrent setexec setfscreate setrlimit execmem execstack execheap }; allow ssh_t self:fd use; allow ssh_t self:fifo_file rw_fifo_file_perms;