From b56ecb9d52d94e27b3bbd27b3e520045a683ec6a Mon Sep 17 00:00:00 2001 From: Dominick Grift Date: Sat, 9 Nov 2013 10:45:08 +0100 Subject: [PATCH] libraries: for now i can only confirm mmap, might need to be changed to bin_t later if it turns out to need execute_no_trans Signed-off-by: Dominick Grift --- policy/modules/system/libraries.fc | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/policy/modules/system/libraries.fc b/policy/modules/system/libraries.fc index 73bb3c00c..d9408e6cc 100644 --- a/policy/modules/system/libraries.fc +++ b/policy/modules/system/libraries.fc @@ -117,6 +117,10 @@ ifdef(`distro_redhat',` /usr/(.*/)?nvidia/.+\.so(\..*)? -- gen_context(system_u:object_r:textrel_shlib_t,s0) +ifdef(`distro_debian',` +/usr/(.*/)?dh-python/dh_pypy -- gen_context(system_u:object_r:lib_t,s0) +') + /usr/lib/altivec/libavcodec\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0) /usr/lib/cedega/.+\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0) /usr/lib/dovecot/(.*/)?lib.*\.so.* -- gen_context(system_u:object_r:lib_t,s0)