From 7a1260ffe3e20b83447c08a2f1ee3912437052e4 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Sat, 13 Jul 2019 14:03:46 -0400 Subject: [PATCH] knot: Whitespace changes. Signed-off-by: Chris PeBenito --- policy/modules/services/knot.fc | 6 +++--- policy/modules/services/knot.te | 4 ++-- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/policy/modules/services/knot.fc b/policy/modules/services/knot.fc index bbf8a3526..258c30cf4 100644 --- a/policy/modules/services/knot.fc +++ b/policy/modules/services/knot.fc @@ -1,11 +1,11 @@ /etc/rc\.d/init\.d/knot -- gen_context(system_u:object_r:knot_initrc_exec_t,s0) -/etc/knot(/.*)? gen_context(system_u:object_r:knot_conf_t,s0) +/etc/knot(/.*)? gen_context(system_u:object_r:knot_conf_t,s0) /usr/sbin/knotd -- gen_context(system_u:object_r:knotd_exec_t,s0) /usr/sbin/knotc -- gen_context(system_u:object_r:knotc_exec_t,s0) -/var/lib/knot(/.*)? gen_context(system_u:object_r:knot_var_lib_t,s0) +/var/lib/knot(/.*)? gen_context(system_u:object_r:knot_var_lib_t,s0) -/run/knot(/.*)? gen_context(system_u:object_r:knot_runtime_t,s0) +/run/knot(/.*)? gen_context(system_u:object_r:knot_runtime_t,s0) diff --git a/policy/modules/services/knot.te b/policy/modules/services/knot.te index 04a9aff00..e0675b203 100644 --- a/policy/modules/services/knot.te +++ b/policy/modules/services/knot.te @@ -36,6 +36,7 @@ files_tmp_file(knot_tmp_t) # # knotd local policy # + allow knotd_t self:capability { dac_override dac_read_search setgid setpcap setuid }; allow knotd_t self:process { signal_perms getcap getsched setsched }; allow knotd_t self:tcp_socket create_stream_socket_perms; @@ -44,7 +45,6 @@ allow knotd_t self:unix_stream_socket create_stream_socket_perms; corenet_tcp_bind_generic_node(knotd_t) corenet_udp_bind_generic_node(knotd_t) - corenet_sendrecv_dns_server_packets(knotd_t) corenet_tcp_bind_dns_port(knotd_t) corenet_udp_bind_dns_port(knotd_t) @@ -77,7 +77,6 @@ files_map_etc_files(knotd_t) files_search_var_lib(knotd_t) fs_getattr_xattr_fs(knotd_t) - fs_getattr_tmpfs(knotd_t) auth_use_nsswitch(knotd_t) @@ -90,6 +89,7 @@ miscfiles_read_localization(knotd_t) # # knotc local policy # + allow knotc_t self:capability { dac_override dac_read_search }; allow knotc_t self:process signal;