add in a couple missing rules
This commit is contained in:
parent
ca3c73d4e6
commit
6942484b6f
|
@ -161,11 +161,15 @@ kernel_list_proc(ypserv_t)
|
|||
kernel_read_proc_symlinks(ypserv_t)
|
||||
|
||||
corenet_tcp_sendrecv_all_if(ypserv_t)
|
||||
corenet_udp_sendrecv_all_if(ypserv_t)
|
||||
corenet_raw_sendrecv_all_if(ypserv_t)
|
||||
corenet_tcp_sendrecv_all_nodes(ypserv_t)
|
||||
corenet_udp_sendrecv_all_nodes(ypserv_t)
|
||||
corenet_raw_sendrecv_all_nodes(ypserv_t)
|
||||
corenet_tcp_sendrecv_all_ports(ypserv_t)
|
||||
corenet_udp_sendrecv_all_ports(ypserv_t)
|
||||
corenet_tcp_bind_all_nodes(ypserv_t)
|
||||
corenet_udp_bind_all_nodes(ypserv_t)
|
||||
corenet_tcp_bind_reserved_port(ypserv_t)
|
||||
corenet_udp_bind_reserved_port(ypserv_t)
|
||||
corenet_dontaudit_tcp_bind_all_reserved_ports(ypserv_t)
|
||||
|
|
|
@ -57,11 +57,15 @@ kernel_read_kernel_sysctl(zebra_t)
|
|||
kernel_rw_net_sysctl(zebra_t)
|
||||
|
||||
corenet_tcp_sendrecv_all_if(zebra_t)
|
||||
corenet_udp_sendrecv_all_if(zebra_t)
|
||||
corenet_raw_sendrecv_all_if(zebra_t)
|
||||
corenet_tcp_sendrecv_all_nodes(zebra_t)
|
||||
corenet_udp_sendrecv_all_nodes(zebra_t)
|
||||
corenet_raw_sendrecv_all_nodes(zebra_t)
|
||||
corenet_tcp_sendrecv_all_ports(zebra_t)
|
||||
corenet_udp_sendrecv_all_ports(zebra_t)
|
||||
corenet_tcp_bind_all_nodes(zebra_t)
|
||||
corenet_udp_bind_all_nodes(zebra_t)
|
||||
corenet_tcp_bind_zebra_port(zebra_t)
|
||||
|
||||
dev_read_sysfs(zebra_t)
|
||||
|
|
|
@ -228,7 +228,7 @@ interface(`libs_use_shared_libs',`
|
|||
class file { rx_file_perms execmod };
|
||||
')
|
||||
|
||||
files_search_usr($1)
|
||||
files_list_usr($1)
|
||||
allow $1 lib_t:dir r_dir_perms;
|
||||
allow $1 lib_t:lnk_file r_file_perms;
|
||||
allow $1 { shlib_t texrel_shlib_t }:lnk_file r_file_perms;
|
||||
|
|
Loading…
Reference in New Issue