Skip to content
Snippets Groups Projects
debuggerd.te 569 B
Newer Older
  • Learn to ignore specific revisions
  • Stephen Smalley's avatar
    Stephen Smalley committed
    # debugger interface
    type debuggerd, domain;
    type debuggerd_exec, exec_type, file_type;
    
    init_daemon_domain(debuggerd)
    typeattribute debuggerd mlstrustedsubject;
    allow debuggerd self:capability { dac_override sys_ptrace chown kill };
    allow debuggerd domain:dir r_dir_perms;
    allow debuggerd domain:file r_file_perms;
    allow debuggerd domain:process ptrace;
    allow debuggerd tombstone_data_file:dir create_dir_perms;
    allow debuggerd tombstone_data_file:file create_file_perms;
    allow debuggerd domain:process { sigstop signal };
    allow debuggerd exec_type:file r_file_perms;