-/etank/games/quake2/quake2/quake2ded -- gen_context(system_u:object_r:quake2_exec_t,s0)
-/etank/games/quake2/quake2/.*/gamex86_64.so -- gen_context(system_u:object_r:quake2_exec_t,s0)
-/etank/games/quake2/quake2(/.*)? gen_context(system_u:object_r:quake2_ro_t,s0)
-/etank/games/quake2/quake2/lithium/save(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
-/etank/games/quake2/quake2/lithium/log(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
-/etank/games/quake2/quake2/lithium/.*log gen_context(system_u:object_r:quake2_rw_t,s0)
-#/etank/games/quake2/.quake2(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
+/etank/games/quake2/quake2/quake2ded([^/]*)? -- gen_context(system_u:object_r:quake2_exec_t,s0)
+/etank/games/quake2/quake2/.*/game(x86_64|i386)\.so -- gen_context(system_u:object_r:quake2_exec_t,s0)
+/etank/games/quake2/quake2(/.*)? gen_context(system_u:object_r:quake2_ro_t,s0)
+/etank/games/quake2/quake2/lithium/save(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
+/etank/games/quake2/quake2/lithium/log(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
+/etank/games/quake2/quake2/lithium/.*log gen_context(system_u:object_r:quake2_rw_t,s0)
+#/etank/games/quake2/.quake2(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0)
-policy_module(quake2, 0.1.1)
+policy_module(quake2, 0.1.5)
# File context for the executable process
type quake2_t;
sysnet_dns_name_resolve(quake2_t)
files_tmp_filetrans(quake2_t, quake2_tmp_t, { file dir})
+
+allow quake2_t self:process execmem;