From: nicolas.iooss@m4x.org (Nicolas Iooss)
Date: Sun, 7 Sep 2014 23:28:11 +0200
Subject: [refpolicy] [PATCH v2 2/7] Introduce init_search_run interface
In-Reply-To: <1410125296-26728-1-git-send-email-nicolas.iooss@m4x.org>
References: <1410125296-26728-1-git-send-email-nicolas.iooss@m4x.org>
Message-ID: <1410125296-26728-2-git-send-email-nicolas.iooss@m4x.org>
To: refpolicy@oss.tresys.com
List-Id: refpolicy.oss.tresys.com
---
policy/modules/system/init.if | 19 +++++++++++++++++++
1 file changed, 19 insertions(+)
diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if
index 15483b04d67f..921796e547e3 100644
--- a/policy/modules/system/init.if
+++ b/policy/modules/system/init.if
@@ -1594,6 +1594,25 @@ interface(`init_dontaudit_read_script_status_files',`
dontaudit $1 initrc_state_t:file read_file_perms;
')
+######################################
+##
+## Search the /run/systemd directory.
+##
+##
+##
+## Domain allowed access.
+##
+##
+#
+interface(`init_search_run',`
+ gen_require(`
+ type init_var_run_t;
+ ')
+
+ files_search_pids($1)
+ allow $1 init_var_run_t:dir search_dir_perms;
+')
+
########################################
##
## Read init script temporary data.
--
2.1.0