From c311426ae9d91f26735123b79e7bdb42281dde5f Mon Sep 17 00:00:00 2001 From: Ralf Ertzinger Date: Fri, 14 Nov 2014 17:16:11 +0000 Subject: [PATCH] Add quake2 --- quake2/quake2.fc | 7 +++++++ quake2/quake2.if | 1 + quake2/quake2.te | 32 ++++++++++++++++++++++++++++++++ 3 files changed, 40 insertions(+) create mode 100644 quake2/quake2.fc create mode 100644 quake2/quake2.if create mode 100644 quake2/quake2.te diff --git a/quake2/quake2.fc b/quake2/quake2.fc new file mode 100644 index 0000000..0ae0145 --- /dev/null +++ b/quake2/quake2.fc @@ -0,0 +1,7 @@ +/etank/games/quake2/quake2/quake2ded -- gen_context(system_u:object_r:quake2_exec_t,s0) +/etank/games/quake2/quake2/.*/gamex86_64.so -- gen_context(system_u:object_r:quake2_exec_t,s0) +/etank/games/quake2/quake2(/.*)? gen_context(system_u:object_r:quake2_ro_t,s0) +/etank/games/quake2/quake2/lithium/save(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0) +/etank/games/quake2/quake2/lithium/log(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0) +/etank/games/quake2/quake2/lithium/.*log gen_context(system_u:object_r:quake2_rw_t,s0) +#/etank/games/quake2/.quake2(/.*)? gen_context(system_u:object_r:quake2_rw_t,s0) diff --git a/quake2/quake2.if b/quake2/quake2.if new file mode 100644 index 0000000..3eb6a30 --- /dev/null +++ b/quake2/quake2.if @@ -0,0 +1 @@ +## diff --git a/quake2/quake2.te b/quake2/quake2.te new file mode 100644 index 0000000..6215cf7 --- /dev/null +++ b/quake2/quake2.te @@ -0,0 +1,32 @@ +policy_module(quake2, 0.1.0) + +# File context for the executable process +type quake2_t; +type quake2_exec_t; + +type quake2_rw_t; +files_type(quake2_rw_t) + +type quake2_ro_t; +files_type(quake2_ro_t) + +type quake2_tmp_t; +files_tmp_file(quake2_tmp_t) + +init_daemon_domain(quake2_t, quake2_exec_t) + +corenet_udp_sendrecv_generic_port(quake2_t) +corenet_udp_bind_generic_port(quake2_t) +corenet_udp_bind_generic_node(quake2_t) + +allow quake2_t quake2_ro_t:dir list_dir_perms; +allow quake2_t quake2_ro_t:file read_file_perms; +#allow quake2_t quake2_tmp_t:file manage_file_perms; +#allow quake2_t quake2_tmp_t:dir manage_dir_perms; + +manage_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t) +manage_dirs_pattern(quake2_t, quake2_rw_t, quake2_rw_t) +setattr_files_pattern(quake2_t, quake2_rw_t, quake2_rw_t) + +sysnet_dns_name_resolve(quake2_t) +files_tmp_filetrans(quake2_t, quake2_tmp_t, { file dir}) -- 1.8.3.1