Blame SOURCES/fapolicyd-selinux.patch

fa39dc
diff -up ./fapolicyd-selinux-0.4/fapolicyd.te.selinux ./fapolicyd-selinux-0.4/fapolicyd.te
fa39dc
--- ./fapolicyd-selinux-0.4/fapolicyd.te.selinux	2021-03-23 10:21:31.000000000 +0100
fa39dc
+++ ./fapolicyd-selinux-0.4/fapolicyd.te	2022-06-29 12:06:57.958124735 +0200
fa39dc
@@ -61,25 +61,15 @@ corecmd_exec_bin(fapolicyd_t)
fb8a4e
 
fa39dc
 domain_read_all_domains_state(fapolicyd_t)
fa39dc
 
fa39dc
-files_mmap_usr_files(fapolicyd_t)
fa39dc
+files_mmap_all_files(fapolicyd_t)
fb8a4e
 files_read_all_files(fapolicyd_t)
fb8a4e
-files_watch_mount_generic_tmp_dirs(fapolicyd_t)
fb8a4e
-files_watch_with_perm_generic_tmp_dirs(fapolicyd_t)
fb8a4e
-files_watch_mount_root_dirs(fapolicyd_t)
fb8a4e
-files_watch_with_perm_root_dirs(fapolicyd_t)
fb8a4e
 
fb8a4e
 fs_getattr_xattr_fs(fapolicyd_t)
fb8a4e
-fs_watch_mount_tmpfs_dirs(fapolicyd_t)
fb8a4e
-fs_watch_with_perm_tmpfs_dirs(fapolicyd_t)
fb8a4e
 
fb8a4e
 logging_send_syslog_msg(fapolicyd_t)
fb8a4e
 dbus_system_bus_client(fapolicyd_t)
fb8a4e
 
fb8a4e
-userdom_watch_mount_tmp_dirs(fapolicyd_t)
fb8a4e
-userdom_watch_with_perm_tmp_dirs(fapolicyd_t)
fb8a4e
-
fb8a4e
 optional_policy(`
fb8a4e
         rpm_read_db(fapolicyd_t)
fb8a4e
-        allow fapolicyd_t rpm_var_lib_t:file { create };
fb8a4e
-        allow fapolicyd_t rpm_var_lib_t:dir { add_name write };
fb8a4e
+        rpm_manage_db(fapolicyd_t)
fb8a4e
 ')