|
|
f939a2 |
diff --git a/sbd.te b/sbd.te
|
|
|
f939a2 |
index 0ba6d491f..927cb8f64 100644
|
|
|
f939a2 |
--- a/sbd.te
|
|
|
f939a2 |
+++ b/sbd.te
|
|
|
f939a2 |
@@ -37,6 +37,8 @@ manage_files_pattern(sbd_t, sbd_tmpfs_t, sbd_tmpfs_t)
|
|
|
f939a2 |
manage_dirs_pattern(sbd_t, sbd_tmpfs_t, sbd_tmpfs_t)
|
|
|
f939a2 |
fs_tmpfs_filetrans(sbd_t, sbd_tmpfs_t, { file dir })
|
|
|
f939a2 |
|
|
|
f939a2 |
+auth_use_nsswitch(sbd_t)
|
|
|
f939a2 |
+
|
|
|
f939a2 |
kernel_read_system_state(sbd_t)
|
|
|
f939a2 |
kernel_dgram_send(sbd_t)
|
|
|
f939a2 |
kernel_rw_all_sysctls(sbd_t)
|
|
|
7d8214 |
diff --git a/tmpreaper.te b/tmpreaper.te
|
|
|
7d8214 |
index a00757adc..0aca5b5fb 100644
|
|
|
7d8214 |
--- a/tmpreaper.te
|
|
|
7d8214 |
+++ b/tmpreaper.te
|
|
|
7d8214 |
@@ -40,18 +40,27 @@ init_nnp_daemon_domain(tmpreaper_t)
|
|
|
7d8214 |
# Local Policy
|
|
|
7d8214 |
#
|
|
|
7d8214 |
|
|
|
7d8214 |
-allow tmpreaper_t self:capability { dac_override dac_read_search fowner };
|
|
|
7d8214 |
+allow tmpreaper_t self:capability { dac_override dac_read_search fowner sys_ptrace };
|
|
|
7d8214 |
allow tmpreaper_t self:fifo_file rw_fifo_file_perms;
|
|
|
7d8214 |
|
|
|
7d8214 |
kernel_list_unlabeled(tmpreaper_t)
|
|
|
7d8214 |
kernel_read_system_state(tmpreaper_t)
|
|
|
7d8214 |
+kernel_read_network_state(tmpreaper_t)
|
|
|
7d8214 |
kernel_delete_unlabeled(tmpreaper_t)
|
|
|
7d8214 |
+kernel_dontaudit_getattr_all_sysctls(tmpreaper_t)
|
|
|
7d8214 |
|
|
|
7d8214 |
dev_read_urand(tmpreaper_t)
|
|
|
7d8214 |
+dev_getattr_all_chr_files(tmpreaper_t)
|
|
|
7d8214 |
+dev_getattr_all_blk_files(tmpreaper_t)
|
|
|
7d8214 |
+dev_getattr_mtrr_dev(tmpreaper_t)
|
|
|
7d8214 |
|
|
|
7d8214 |
corecmd_exec_bin(tmpreaper_t)
|
|
|
7d8214 |
corecmd_exec_shell(tmpreaper_t)
|
|
|
7d8214 |
|
|
|
7d8214 |
+domain_read_all_domains_state(tmpreaper_t)
|
|
|
7d8214 |
+domain_getattr_all_sockets(tmpreaper_t)
|
|
|
7d8214 |
+domain_getattr_all_pipes(tmpreaper_t)
|
|
|
7d8214 |
+
|
|
|
7d8214 |
fs_getattr_xattr_fs(tmpreaper_t)
|
|
|
7d8214 |
fs_list_all(tmpreaper_t)
|
|
|
7d8214 |
fs_setattr_tmpfs_dirs(tmpreaper_t)
|