fapolicyd/0100-Improve-install-process.patch
Petr Lautrbach ea744010c8 Install SELinux policy hardening module
fapolicyd-hardening module prevents usage of sigstop, sigkill and ptrace

Resolves: RHEL-1368
2025-11-07 17:39:40 +01:00

31 lines
1.3 KiB
Diff

From 39acf75fff8fa706e75ef512a81e7b1850bfa0c4 Mon Sep 17 00:00:00 2001
From: Petr Lautrbach <lautrbach@redhat.com>
Date: Thu, 6 Nov 2025 16:36:28 +0100
Subject: [PATCH] Improve install process
Content-type: text/plain
- install fapolicyd-hardening.cil together with fapolicyd.pp.bz2
- follow the guidelines and install interface file to
${SHAREDIR}/selinux/devel/include/distributed see
https://fedoraproject.org/wiki/SELinux/IndependentPolicy#Using_custom_interfaces
---
Makefile | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/fapolicyd-selinux-1.0/Makefile b/fapolicyd-selinux-1.0/Makefile
index b3dcfefca061..9fe67f3a2a7c 100644
--- a/fapolicyd-selinux-1.0/Makefile
+++ b/fapolicyd-selinux-1.0/Makefile
@@ -39,6 +39,7 @@ install-policy: all
install: man
install -D -m 644 ${TARGETS}.pp.bz2 ${DESTDIR}${SHAREDIR}/selinux/packages/${TARGETS}.pp.bz2
- install -D -m 644 ${TARGETS}.if ${DESTDIR}${SHAREDIR}/selinux/devel/include/services/${TARGETS}.if
+ install -D -m 644 ${TARGETS}-hardening.cil ${DESTDIR}${SHAREDIR}/selinux/packages/${TARGETS}-hardening.cil
+ install -D -m 644 ${TARGETS}.if ${DESTDIR}${SHAREDIR}/selinux/devel/include/distributed/${TARGETS}.if
install -D -m 644 ${TARGETS}_selinux.8 ${DESTDIR}${SHAREDIR}/man/man8/
--
2.51.1