From ef854630b4155968cce57957910450670b976a52 Mon Sep 17 00:00:00 2001 From: Laurent Bigonville Date: Tue, 15 Jan 2013 11:23:39 +0100 Subject: [PATCH] Label var_lock_t as a mountpoint In Debian, /var/lock is a symlink to /var/run/lock which is a tmpfs mount. --- policy/modules/kernel/files.te | 1 + 1 file changed, 1 insertion(+) diff --git a/policy/modules/kernel/files.te b/policy/modules/kernel/files.te index 148d87aa0..4a59c7682 100644 --- a/policy/modules/kernel/files.te +++ b/policy/modules/kernel/files.te @@ -173,6 +173,7 @@ files_mountpoint(var_lib_t) # type var_lock_t; files_lock_file(var_lock_t) +files_mountpoint(var_lock_t) # # var_run_t is the type of /var/run, usually