From: nicolas.iooss@m4x.org (Nicolas Iooss) Date: Sun, 7 Sep 2014 23:28:11 +0200 Subject: [refpolicy] [PATCH v2 2/7] Introduce init_search_run interface In-Reply-To: <1410125296-26728-1-git-send-email-nicolas.iooss@m4x.org> References: <1410125296-26728-1-git-send-email-nicolas.iooss@m4x.org> Message-ID: <1410125296-26728-2-git-send-email-nicolas.iooss@m4x.org> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com --- policy/modules/system/init.if | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if index 15483b04d67f..921796e547e3 100644 --- a/policy/modules/system/init.if +++ b/policy/modules/system/init.if @@ -1594,6 +1594,25 @@ interface(`init_dontaudit_read_script_status_files',` dontaudit $1 initrc_state_t:file read_file_perms; ') +###################################### +## +## Search the /run/systemd directory. +## +## +## +## Domain allowed access. +## +## +# +interface(`init_search_run',` + gen_require(` + type init_var_run_t; + ') + + files_search_pids($1) + allow $1 init_var_run_t:dir search_dir_perms; +') + ######################################## ## ## Read init script temporary data. -- 2.1.0