diff --git a/policy/modules/system/authlogin.if b/policy/modules/system/authlogin.if index 899171aa2..62e0e0585 100644 --- a/policy/modules/system/authlogin.if +++ b/policy/modules/system/authlogin.if @@ -845,6 +845,24 @@ interface(`auth_rw_shadow_lock',` rw_files_pattern($1, shadow_lock_t, shadow_lock_t) ') +######################################## +## +## Search faillock directory (/run/faillock). +## +## +## +## Domain allowed access. +## +## +# +interface(`auth_search_faillog',` + gen_require(` + type faillog_t; + ') + + allow $1 faillog_t:dir search_dir_perms; +') + ####################################### ## ## Append to the login failure log. diff --git a/policy/modules/system/selinuxutil.te b/policy/modules/system/selinuxutil.te index fb4dddc29..ebc1abc10 100644 --- a/policy/modules/system/selinuxutil.te +++ b/policy/modules/system/selinuxutil.te @@ -294,6 +294,7 @@ auth_use_nsswitch(newrole_t) auth_run_chk_passwd(newrole_t, newrole_roles) auth_run_upd_passwd(newrole_t, newrole_roles) auth_rw_faillog(newrole_t) +auth_search_faillog(newrole_t) # Write to utmp. init_rw_utmp(newrole_t)