selinux-refpolicy/policy/modules/admin/usbguard.fc
Topi Miettinen 1d2fb171b5
Add usbguard
Usbguard enforces the USB device authorization policy for all USB
devices. Users can be authorized to manage rules and make device
authorization decisions using a command line tool.

Add rules for usbguard. Optionally, allow authorized users to control
the daemon, which requires usbguard-daemon to be able modify its rules
in /etc/usbguard.

Signed-off-by: Topi Miettinen <toiwoton@gmail.com>
2020-03-18 20:23:38 +02:00

8 lines
389 B
Plaintext

/etc/usbguard -d gen_context(system_u:object_r:usbguard_conf_t,s0)
/etc/usbguard/rules\.conf gen_context(system_u:object_r:usbguard_rules_t,s0)
/etc/usbguard/.+ gen_context(system_u:object_r:usbguard_conf_t,s0)
/usr/sbin/usbguard-daemon -- gen_context(system_u:object_r:usbguard_daemon_exec_t,s0)
/var/log/usbguard(/.*)? gen_context(system_u:object_r:usbguard_log_t,s0)