Call init_domain() in addition to init_daemon_domain(), this adds permissions needed...
[selinux.git] / quake2 / quake2.te
1 policy_module(quake2, 0.1.11)
2
3 # File context for the executable process
4 type quake2_t;
5 type quake2_exec_t;
6
7 type quake2_rw_t;
8 files_type(quake2_rw_t)
9
10 type quake2_ro_t;
11 files_type(quake2_ro_t)
12
13 _sky_files_use_tmp(quake2_t, quake2_tmp_t)
14
15 init_domain(quake2_t, quake2_exec_t)
16 init_daemon_domain(quake2_t, quake2_exec_t)
17
18 corenet_udp_sendrecv_generic_port(quake2_t)
19 corenet_udp_bind_generic_port(quake2_t)
20 corenet_udp_bind_generic_node(quake2_t)
21
22 read_files_pattern(quake2_t, quake2_ro_t, quake2_ro_t)
23 list_dirs_pattern(quake2_t, quake2_ro_t, quake2_ro_t)
24
25 manage_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t)
26 manage_dirs_pattern(quake2_t, quake2_rw_t, quake2_rw_t)
27 setattr_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t)
28
29 sysnet_dns_name_resolve(quake2_t)
30
31 allow quake2_t self:process execmem;