chkrootkit: add interfaces and sysadm permit

v2:
 - add bin_t fc to corecommands
This commit is contained in:
cgzones 2017-06-09 15:37:16 +02:00 committed by Chris PeBenito
parent 5ab11a8454
commit c6f76058dc
3 changed files with 23 additions and 0 deletions

View File

@ -416,6 +416,7 @@ ifdef(`distro_suse', `
/var/ftp/bin(/.*)? gen_context(system_u:object_r:bin_t,s0)
/var/lib/asterisk/agi-bin(/.*)? gen_context(system_u:object_r:bin_t,s0)
/usr/lib/chkrootkit/.* -- gen_context(system_u:object_r:bin_t,s0)
/usr/lib/yp/.+ -- gen_context(system_u:object_r:bin_t,s0)
/var/qmail/bin -d gen_context(system_u:object_r:bin_t,s0)

View File

@ -235,6 +235,10 @@ optional_policy(`
cgroup_admin(sysadm_t, sysadm_r)
')
optional_policy(`
chkrootkit_run(sysadm_t, sysadm_r)
')
optional_policy(`
chronyd_admin(sysadm_t, sysadm_r)
')

View File

@ -677,6 +677,24 @@ interface(`init_getpgid',`
allow $1 init_t:process getpgid;
')
########################################
## <summary>
## Send init a generic signal.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`init_signal',`
gen_require(`
type init_t;
')
allow $1 init_t:process signal;
')
########################################
## <summary>
## Send init a null signal.