diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if index e6e831c..a7db5fe 100644 --- a/policy/modules/system/init.if +++ b/policy/modules/system/init.if @@ -695,6 +695,31 @@ interface(`init_script_file_domtrans',` ######################################## ## +## Transition to the init script domain +## on a specified labeled init script. +## +## +## +## Domain allowed access. +## +## +## +## +## Labeled init script file. +## +## +# +interface(`init_labeled_script_domtrans',` + gen_require(` + type initrc_t; + ') + + domtrans_pattern($1, $2, initrc_t) + files_search_etc($1) +') + +######################################## +## ## Start and stop daemon programs directly. ## ## diff --git a/policy/modules/system/init.te b/policy/modules/system/init.te index 751a0f7..3e03dac 100644 --- a/policy/modules/system/init.te +++ b/policy/modules/system/init.te @@ -1,5 +1,5 @@ -policy_module(init, 1.11.3) +policy_module(init, 1.11.4) gen_require(` class passwd rootok;