mirror of
https://github.com/SELinuxProject/refpolicy
synced 2025-03-29 14:56:29 +00:00
rkhunter: add interfaces for var_run and lock dir access check
This commit is contained in:
parent
c974aa56b1
commit
ff0937af03
@ -5816,6 +5816,25 @@ interface(`files_list_locks',`
|
||||
list_dirs_pattern($1, var_t, var_lock_t)
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Test write access on lock directories.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`files_check_write_lock_dirs',`
|
||||
gen_require(`
|
||||
type var_lock_t;
|
||||
')
|
||||
|
||||
allow $1 var_lock_t:lnk_file read_lnk_file_perms;
|
||||
allow $1 var_lock_t:dir write;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Add entries in the /var/lock directories.
|
||||
@ -6222,6 +6241,24 @@ interface(`files_create_pid_dirs',`
|
||||
allow $1 var_run_t:dir create_dir_perms;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Check write access on /var/run directories.
|
||||
## </summary>
|
||||
## <param name="domain">
|
||||
## <summary>
|
||||
## Domain allowed access.
|
||||
## </summary>
|
||||
## </param>
|
||||
#
|
||||
interface(`files_check_write_pid_dirs',`
|
||||
gen_require(`
|
||||
type var_run_t;
|
||||
')
|
||||
|
||||
allow $1 var_run_t:dir write;
|
||||
')
|
||||
|
||||
########################################
|
||||
## <summary>
|
||||
## Read generic process ID files.
|
||||
|
Loading…
Reference in New Issue
Block a user