selinux-refpolicy/policy/modules/services/cgmanager.fc
Nicolas Iooss f0cade07b2
Remove unescaped single dot from the policy
In a pattern, a dot can match any character, including slash. It makes
sense when it is combined with ?, + or *, but makes little sense when
left alone.

Most of the time, the label was for file containing dots, where the dot
was not escaped. A few times, the dot was really intended to match any
character. In such case, [^/] better suits the intent.

Signed-off-by: Nicolas Iooss <nicolas.iooss@m4x.org>
2019-08-27 23:38:09 +02:00

14 lines
674 B
Plaintext

/sys/fs/cgroup/cgmanager(/.*)? gen_context(system_u:object_r:cgmanager_cgroup_t,s0)
/run/cgmanager(/.*)? gen_context(system_u:object_r:cgmanager_run_t,s0)
/run/cgmanager\.pid gen_context(system_u:object_r:cgmanager_run_t,s0)
/run/cgmanager/fs(/.*)? <<none>>
/usr/bin/cgmanager -- gen_context(system_u:object_r:cgmanager_exec_t,s0)
/usr/bin/cgproxy -- gen_context(system_u:object_r:cgmanager_exec_t,s0)
/usr/libexec/cgmanager/cgm-release-agent -- gen_context(system_u:object_r:cgmanager_exec_t,s0)
/usr/sbin/cgmanager -- gen_context(system_u:object_r:cgmanager_exec_t,s0)
/usr/sbin/cgproxy -- gen_context(system_u:object_r:cgmanager_exec_t,s0)