usbguard/selinux.patch
Radovan Sroka 578d15f9f1
Fixed selinux issue
Signed-off-by: Radovan Sroka <rsroka@redhat.com>
2019-12-18 18:04:25 +01:00

33 lines
1.2 KiB
Diff

diff -up ./usbguard-selinux-0.0.2/usbguard.te.selinux ./usbguard-selinux-0.0.2/usbguard.te
--- ./usbguard-selinux-0.0.2/usbguard.te.selinux 2019-11-13 07:08:17.000000000 -0500
+++ ./usbguard-selinux-0.0.2/usbguard.te 2019-12-18 11:21:36.725889798 -0500
@@ -41,15 +41,18 @@ gen_tunable(usbguard_daemon_write_rules,
type usbguard_t;
type usbguard_exec_t;
init_daemon_domain(usbguard_t, usbguard_exec_t)
+init_nnp_daemon_domain(usbguard_t)
type usbguard_unit_file_t;
systemd_unit_file(usbguard_unit_file_t)
type usbguard_conf_t;
files_config_file(usbguard_conf_t)
+systemd_mount_dir(usbguard_conf_t)
type usbguard_log_t;
logging_log_file(usbguard_log_t)
+systemd_mount_dir(usbguard_log_t)
type usbguard_rules_t;
files_config_file(usbguard_rules_t)
@@ -84,7 +87,8 @@ manage_files_pattern(usbguard_t, usbguar
files_pid_filetrans(usbguard_t, usbguard_var_run_t, file)
manage_files_pattern(usbguard_t, usbguard_tmpfs_t, usbguard_tmpfs_t)
-fs_tmpfs_filetrans(usbguard_t, usbguard_tmpfs_t, file)
+fs_tmpfs_filetrans(usbguard_t, usbguard_tmpfs_t, { file dir })
+manage_dirs_pattern(usbguard_t, usbguard_tmpfs_t, usbguard_tmpfs_t)
allow usbguard_t usbguard_tmpfs_t:file map;
manage_files_pattern(usbguard_t, usbguard_log_t, usbguard_log_t)