From b40dc4f657c47c96afd3bd8520f34cc4446bd8b8 Mon Sep 17 00:00:00 2001 From: Laurent Bigonville Date: Sat, 12 Jan 2013 22:32:19 +0100 Subject: [PATCH] Label /var/run/shm as tmpfs_t for Debian In Debian, /dev/shm is a symlink to /var/run/shm. Label that mountpoint the same way. --- policy/modules/kernel/filesystem.fc | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/policy/modules/kernel/filesystem.fc b/policy/modules/kernel/filesystem.fc index cda5588eb..3d67e80e3 100644 --- a/policy/modules/kernel/filesystem.fc +++ b/policy/modules/kernel/filesystem.fc @@ -14,3 +14,8 @@ # for systemd systems: /sys/fs/cgroup -d gen_context(system_u:object_r:cgroup_t,s0) /sys/fs/cgroup/.* <> + +ifdef(`distro_debian',` +/var/run/shm -d gen_context(system_u:object_r:tmpfs_t,s0) +/var/run/shm/.* <> +')