1 |
commit: 2a706fe10f808aac846cef19c5362a22a6e5253c |
2 |
Author: Chris PeBenito <pebenito <AT> ieee <DOT> org> |
3 |
AuthorDate: Thu Jan 28 15:51:39 2021 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Mon Feb 1 01:21:42 2021 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=2a706fe1 |
7 |
|
8 |
file_patterns.spt: Add a mmap_manage_files_pattern(). |
9 |
|
10 |
Signed-off-by: Chris PeBenito <pebenito <AT> ieee.org> |
11 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
12 |
|
13 |
policy/support/file_patterns.spt | 5 +++++ |
14 |
1 file changed, 5 insertions(+) |
15 |
|
16 |
diff --git a/policy/support/file_patterns.spt b/policy/support/file_patterns.spt |
17 |
index 6ce53fa9..19fcf275 100644 |
18 |
--- a/policy/support/file_patterns.spt |
19 |
+++ b/policy/support/file_patterns.spt |
20 |
@@ -154,6 +154,11 @@ define(`manage_files_pattern',` |
21 |
allow $1 $3:file manage_file_perms; |
22 |
') |
23 |
|
24 |
+define(`mmap_manage_files_pattern',` |
25 |
+ allow $1 $2:dir rw_dir_perms; |
26 |
+ allow $1 $3:file { manage_file_perms map }; |
27 |
+') |
28 |
+ |
29 |
define(`relabelfrom_files_pattern',` |
30 |
allow $1 $2:dir search_dir_perms; |
31 |
allow $1 $3:file relabelfrom_file_perms; |