- Rebase fapolicyd to the latest stable version Resolves: RHEL-519 - RFE: send rule number to fanotify so it gets audited Resolves: RHEL-628 - Default q_size doesn't match manpage's one Resolves: RHEL-629 - fapolicyd can leak FDs and never answer request, causing target process to hang forever Resolves: RHEL-632 - fapolicyd needs to make sure the FD limit is never reached Resolves: RHEL-631 - fapolicyd still allows execution of a program after "untrusting" it Resolves: RHEL-630 Signed-off-by: Radovan Sroka <rsroka@redhat.com>
14 lines
464 B
Diff
14 lines
464 B
Diff
diff -up ./fapolicyd-selinux-0.6/fapolicyd.te.fix ./fapolicyd-selinux-0.6/fapolicyd.te
|
|
--- ./fapolicyd-selinux-0.6/fapolicyd.te.fix 2023-06-15 17:11:47.964646794 +0200
|
|
+++ ./fapolicyd-selinux-0.6/fapolicyd.te 2023-06-15 17:13:10.426477653 +0200
|
|
@@ -50,6 +50,9 @@ ifdef(`watch_mount_dirs_pattern',`
|
|
|
|
ifdef(`fs_watch_all_fs',`
|
|
fs_watch_all_fs(fapolicyd_t)
|
|
+')
|
|
+
|
|
+ifdef(`files_watch_sb_all_mountpoints',`
|
|
files_watch_sb_all_mountpoints(fapolicyd_t)
|
|
')
|
|
|