X-Git-Url: https://git.camperquake.de/gitweb.cgi?a=blobdiff_plain;f=cod4%2Fcod4.te;h=bc833ab99bfd7ca2cd61ddf5b8d8809d01bade58;hb=HEAD;hp=389e4bc81f1654da67eb08c5f97005e8bb152ee3;hpb=e2c43ce175ce15856f49e04458513569bd7b2d92;p=selinux.git diff --git a/cod4/cod4.te b/cod4/cod4.te index 389e4bc..bc833ab 100644 --- a/cod4/cod4.te +++ b/cod4/cod4.te @@ -1,4 +1,8 @@ -policy_module(cod4, 0.1.30) +policy_module(cod4, 0.1.38) + +require { + type games_data_t; +} # File context for the executable process type cod4_t; @@ -10,6 +14,7 @@ files_type(cod4_rw_t) type cod4_ro_t; files_type(cod4_ro_t) +init_domain(cod4_t, cod4_exec_t) init_daemon_domain(cod4_t, cod4_exec_t) corenet_udp_sendrecv_generic_port(cod4_t) @@ -17,6 +22,7 @@ corenet_udp_bind_generic_port(cod4_t) corenet_udp_bind_generic_node(cod4_t) read_files_pattern(cod4_t, cod4_ro_t, cod4_ro_t) +list_dirs_pattern(cod4_t, cod4_ro_t, cod4_ro_t) manage_files_pattern(cod4_t, cod4_rw_t, cod4_rw_t) manage_dirs_pattern(cod4_t, cod4_rw_t, cod4_rw_t) @@ -25,3 +31,5 @@ setattr_files_pattern(cod4_t, cod4_rw_t, cod4_rw_t) sysnet_dns_name_resolve(cod4_t) allow init_t cod4_t:process { noatsecure }; + +list_dirs_pattern(cod4_t, games_data_t, games_data_t)