X-Git-Url: https://git.camperquake.de/gitweb.cgi?a=blobdiff_plain;f=quake2%2Fquake2.te;h=7ceaf033bcc25cf66c92f93cb8d19ff8d864222a;hb=refs%2Fheads%2Fmaster;hp=6215cf7e9d477a9fe33ae7e1059904e6699aef43;hpb=c311426ae9d91f26735123b79e7bdb42281dde5f;p=selinux.git diff --git a/quake2/quake2.te b/quake2/quake2.te index 6215cf7..7ceaf03 100644 --- a/quake2/quake2.te +++ b/quake2/quake2.te @@ -1,4 +1,8 @@ -policy_module(quake2, 0.1.0) +policy_module(quake2, 0.1.12) + +require { + type games_data_t; +} # File context for the executable process type quake2_t; @@ -10,23 +14,24 @@ files_type(quake2_rw_t) type quake2_ro_t; files_type(quake2_ro_t) -type quake2_tmp_t; -files_tmp_file(quake2_tmp_t) +_sky_files_use_tmp(quake2_t, quake2_tmp_t) +init_domain(quake2_t, quake2_exec_t) init_daemon_domain(quake2_t, quake2_exec_t) corenet_udp_sendrecv_generic_port(quake2_t) corenet_udp_bind_generic_port(quake2_t) corenet_udp_bind_generic_node(quake2_t) -allow quake2_t quake2_ro_t:dir list_dir_perms; -allow quake2_t quake2_ro_t:file read_file_perms; -#allow quake2_t quake2_tmp_t:file manage_file_perms; -#allow quake2_t quake2_tmp_t:dir manage_dir_perms; +read_files_pattern(quake2_t, quake2_ro_t, quake2_ro_t) +list_dirs_pattern(quake2_t, quake2_ro_t, quake2_ro_t) manage_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t) manage_dirs_pattern(quake2_t, quake2_rw_t, quake2_rw_t) setattr_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t) sysnet_dns_name_resolve(quake2_t) -files_tmp_filetrans(quake2_t, quake2_tmp_t, { file dir}) + +allow quake2_t self:process execmem; + +list_dirs_pattern(quake2_t, games_data_t, games_data_t)