fixes to make screen work
This commit is contained in:
parent
4ec6941bfa
commit
038bd3f863
@ -70,6 +70,8 @@ template(`screen_per_userdomain_template',`
|
|||||||
allow $1_screen_t $1_screen_tmp_t:fifo_file create_file_perms;
|
allow $1_screen_t $1_screen_tmp_t:fifo_file create_file_perms;
|
||||||
files_create_tmp_files($1_screen_t, $1_screen_tmp_t, { file dir })
|
files_create_tmp_files($1_screen_t, $1_screen_tmp_t, { file dir })
|
||||||
|
|
||||||
|
allow $1_screen_t $1_devpts_t:chr_file setattr;
|
||||||
|
|
||||||
# Create fifo
|
# Create fifo
|
||||||
allow $1_screen_t screen_dir_t:dir rw_dir_perms;
|
allow $1_screen_t screen_dir_t:dir rw_dir_perms;
|
||||||
allow $1_screen_t screen_dir_t:dir create_dir_perms;
|
allow $1_screen_t screen_dir_t:dir create_dir_perms;
|
||||||
@ -83,7 +85,8 @@ template(`screen_per_userdomain_template',`
|
|||||||
|
|
||||||
domain_auto_trans($2, screen_exec_t, $1_screen_t)
|
domain_auto_trans($2, screen_exec_t, $1_screen_t)
|
||||||
allow $2 $1_screen_t:process signal;
|
allow $2 $1_screen_t:process signal;
|
||||||
allow $1_screen_t $2:process signal;
|
allow $1_screen_t $2:process { signal sigchld };
|
||||||
|
allow $1_screen_t $2:fd use;
|
||||||
allow $1_screen_t $2:fifo_file rw_file_perms;
|
allow $1_screen_t $2:fifo_file rw_file_perms;
|
||||||
allow $1_screen_t $1_home_dir_t:dir { search getattr };
|
allow $1_screen_t $1_home_dir_t:dir { search getattr };
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user