Update selinux-knot policy
This commit is contained in:
parent
c0d3e57721
commit
bf066a6d3a
|
@ -87,9 +87,9 @@ interface(`knot_admin',`
|
||||||
type knot_runtime_t, knot_tmp_t, knot_var_lib_t;
|
type knot_runtime_t, knot_tmp_t, knot_var_lib_t;
|
||||||
')
|
')
|
||||||
|
|
||||||
allow $2 knotc_t:process signal_perms;
|
allow $1 knotc_t:process signal_perms;
|
||||||
allow $1 knotd_t:process { ptrace signal_perms };
|
allow $1 knotd_t:process { ptrace signal_perms };
|
||||||
ps_process_pattern($2, knotc_t)
|
ps_process_pattern($1, knotc_t)
|
||||||
ps_process_pattern($1, knotd_t)
|
ps_process_pattern($1, knotd_t)
|
||||||
|
|
||||||
init_startstop_service($1, $2, knotd_t, knot_initrc_exec_t)
|
init_startstop_service($1, $2, knotd_t, knot_initrc_exec_t)
|
||||||
|
|
|
@ -136,6 +136,6 @@ optional_policy(`
|
||||||
type sysadm_t;
|
type sysadm_t;
|
||||||
')
|
')
|
||||||
|
|
||||||
knot_admin(sysadm_r, sysadm_t)
|
knot_admin(sysadm_t, sysadm_r)
|
||||||
knot_run_client(sysadm_r, sysadm_t)
|
knot_run_client(sysadm_t, sysadm_r)
|
||||||
')
|
')
|
||||||
|
|
Loading…
Reference in New Issue