Skip to content

Commit 3c8356a

Browse files
authored
Merge pull request #1141 from dsugar100/main
fapolicyd: fix issue with tmpfs_t write
2 parents 9db69e4 + 78f8b23 commit 3c8356a

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

policy/modules/admin/fapolicyd.te

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,9 @@ logging_log_file(fapolicyd_log_t)
3838
type fapolicyd_runtime_t;
3939
files_runtime_file(fapolicyd_runtime_t)
4040

41+
type fapolicyd_tmpfs_t;
42+
files_tmpfs_file(fapolicyd_tmpfs_t)
43+
4144
type fagenrules_tmp_t;
4245
files_tmp_file(fagenrules_tmp_t)
4346

@@ -58,6 +61,7 @@ allow fapolicyd_t self:process { setcap setsched };
5861

5962
allow fapolicyd_t fapolicyd_log_t:file { create_file_perms write_file_perms };
6063
allow fapolicyd_t fapolicyd_runtime_t:dir setattr_dir_perms;
64+
allow fapolicyd_t fapolicyd_tmpfs_t:file write_inherited_file_perms;
6165

6266
manage_fifo_files_pattern(fapolicyd_t, fapolicyd_runtime_t, fapolicyd_runtime_t)
6367
manage_files_pattern(fapolicyd_t, fapolicyd_runtime_t, fapolicyd_runtime_t)
@@ -83,6 +87,7 @@ files_watch_all_mount_perm(fapolicyd_t)
8387
files_watch_all_mount_sb(fapolicyd_t)
8488

8589
fs_getattr_xattr_fs(fapolicyd_t)
90+
fs_tmpfs_filetrans(fapolicyd_t, fapolicyd_tmpfs_t, file)
8691
fs_watch_all_fs(fapolicyd_t)
8792

8893
logging_log_filetrans(fapolicyd_t, fapolicyd_log_t, file)

0 commit comments

Comments
 (0)