File lnk_file.patch of Package selinux-policy
diff -r -u selinux-policy-20250627+git66.15675827a/policy/modules/contrib/sap.if selinux-policy-20250627+git66.15675827a.mod/policy/modules/contrib/sap.if
--- selinux-policy-20250627+git66.15675827a/policy/modules/contrib/sap.if 2025-07-30 16:37:13.000000000 +0200
+++ selinux-policy-20250627+git66.15675827a.mod/policy/modules/contrib/sap.if 2025-10-10 08:57:24.452512652 +0200
@@ -37,3 +37,21 @@
corecmd_search_bin($1)
domtrans_pattern($1, sap_exec_t, sap_unconfined_t)
')
+
+#######################################
+## <summary>
+## Read SAP lnk_files.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`sap_read_lnk_files',`
+ gen_require(`
+ type sap_exec_t;
+ ')
+
+ read_lnk_files_pattern($1, sap_exec_t, sap_exec_t)
+')
diff -r -u selinux-policy-20250627+git66.15675827a/policy/modules/system/init.te selinux-policy-20250627+git66.15675827a.mod/policy/modules/system/init.te
--- selinux-policy-20250627+git66.15675827a/policy/modules/system/init.te 2025-07-30 16:37:13.000000000 +0200
+++ selinux-policy-20250627+git66.15675827a.mod/policy/modules/system/init.te 2025-10-10 08:57:24.456512725 +0200
@@ -910,6 +910,10 @@
')
optional_policy(`
+ sap_read_lnk_files(init_t)
+')
+
+optional_policy(`
stratisd_data_read_lnk_files(init_t)
')