diff --git a/private/apexd.te b/private/apexd.te index faff8c659..36b799903 100644 --- a/private/apexd.te +++ b/private/apexd.te @@ -45,7 +45,7 @@ allow apexd dm_device:blk_file rw_file_perms; # sys_admin is required to access the device-mapper and mount # dac_override, chown, and fowner are needed for snapshot and restore -allow apexd self:global_capability_class_set { sys_admin chown dac_override fowner }; +allow apexd self:global_capability_class_set { sys_admin chown dac_override dac_read_search fowner }; # Note: fsetid is deliberately not included above. fsetid checks are # triggered by chmod on a directory or file owned by a group other