rkhunter: add interfaces for var_run and lock dir access check

This commit is contained in:
Christian Göttsche 2017-09-10 17:48:03 +02:00 committed by Chris PeBenito
parent c974aa56b1
commit ff0937af03

View File

@ -5816,6 +5816,25 @@ interface(`files_list_locks',`
list_dirs_pattern($1, var_t, var_lock_t)
')
########################################
## <summary>
## Test write access on lock directories.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`files_check_write_lock_dirs',`
gen_require(`
type var_lock_t;
')
allow $1 var_lock_t:lnk_file read_lnk_file_perms;
allow $1 var_lock_t:dir write;
')
########################################
## <summary>
## Add entries in the /var/lock directories.
@ -6222,6 +6241,24 @@ interface(`files_create_pid_dirs',`
allow $1 var_run_t:dir create_dir_perms;
')
########################################
## <summary>
## Check write access on /var/run directories.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`files_check_write_pid_dirs',`
gen_require(`
type var_run_t;
')
allow $1 var_run_t:dir write;
')
########################################
## <summary>
## Read generic process ID files.