mirror of
https://github.com/SELinuxProject/refpolicy
synced 2025-04-01 00:06:24 +00:00
chkrootkit: add interfaces and sysadm permit
v2: - add bin_t fc to corecommands
This commit is contained in:
parent
5ab11a8454
commit
c6f76058dc
@ -416,6 +416,7 @@ ifdef(`distro_suse', `
|
||||
/var/ftp/bin(/.*)? gen_context(system_u:object_r:bin_t,s0)
|
||||
|
||||
/var/lib/asterisk/agi-bin(/.*)? gen_context(system_u:object_r:bin_t,s0)
|
||||
/usr/lib/chkrootkit/.* -- gen_context(system_u:object_r:bin_t,s0)
|
||||
/usr/lib/yp/.+ -- gen_context(system_u:object_r:bin_t,s0)
|
||||
|
||||
/var/qmail/bin -d gen_context(system_u:object_r:bin_t,s0)
|
||||
|
@ -235,6 +235,10 @@ optional_policy(`
|
||||
cgroup_admin(sysadm_t, sysadm_r)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
chkrootkit_run(sysadm_t, sysadm_r)
|
||||
')
|
||||
|
||||
optional_policy(`
|
||||
chronyd_admin(sysadm_t, sysadm_r)
|
||||
')
|
||||
|
@ -677,6 +677,24 @@ interface(`init_getpgid',`
|
||||
allow $1 init_t:process getpgid;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Send init a generic signal.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`init_signal',`
|
||||
gen_require(`
|
||||
type init_t;
|
||||
')
|
||||
|
||||
allow $1 init_t:process signal;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Send init a null signal.
|
||||
|
Loading…
Reference in New Issue
Block a user