From 687b5d3391a43d80d663725dc5215318d813b511 Mon Sep 17 00:00:00 2001 From: Nicolas Iooss Date: Sun, 7 Sep 2014 23:28:11 +0200 Subject: [PATCH] Introduce init_search_run interface --- policy/modules/system/init.if | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if index 15483b04d..921796e54 100644 --- a/policy/modules/system/init.if +++ b/policy/modules/system/init.if @@ -1594,6 +1594,25 @@ interface(`init_dontaudit_read_script_status_files',` dontaudit $1 initrc_state_t:file read_file_perms; ') +###################################### +## +## Search the /run/systemd directory. +## +## +## +## Domain allowed access. +## +## +# +interface(`init_search_run',` + gen_require(` + type init_var_run_t; + ') + + files_search_pids($1) + allow $1 init_var_run_t:dir search_dir_perms; +') + ######################################## ## ## Read init script temporary data.