add missing dir and file perms for selinuxfs in unconfined
This commit is contained in:
parent
689f6ddb35
commit
1e3f610b3b
|
@ -279,6 +279,8 @@ interface(`selinux_unconfined',`
|
|||
gen_require(`
|
||||
attribute can_load_policy, can_setenforce, can_setsecparam;
|
||||
type security_t;
|
||||
class dir { getattr search read };
|
||||
class file { getattr read write };
|
||||
class security { load_policy setenforce setbool };
|
||||
')
|
||||
|
||||
|
@ -286,5 +288,9 @@ interface(`selinux_unconfined',`
|
|||
allow $1 security_t:security *;
|
||||
auditallow $1 security_t:security { load_policy setenforce setbool };
|
||||
|
||||
# use SELinuxfs
|
||||
allow $1 security_t:dir { getattr search read };
|
||||
allow $1 secuirty_t:file { getattr read write };
|
||||
|
||||
typeattribute $1 can_load_policy, can_setenforce, can_setsecparam;
|
||||
')
|
||||
|
|
Loading…
Reference in New Issue