Introduce init_search_run interface

This commit is contained in:
Nicolas Iooss 2014-09-07 23:28:11 +02:00 committed by Chris PeBenito
parent 8cfe827a3d
commit 687b5d3391

View File

@ -1594,6 +1594,25 @@ interface(`init_dontaudit_read_script_status_files',`
dontaudit $1 initrc_state_t:file read_file_perms;
')
######################################
## <summary>
## Search the /run/systemd directory.
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`init_search_run',`
gen_require(`
type init_var_run_t;
')
files_search_pids($1)
allow $1 init_var_run_t:dir search_dir_perms;
')
########################################
## <summary>
## Read init script temporary data.