diff --git a/untrusted_app.te b/untrusted_app.te index 463745ef1c17729ffbd925c49de37e48e2057cce..38d7472c83e69ba11a9aeca4ecef29ed628f9fc9 100644 --- a/untrusted_app.te +++ b/untrusted_app.te @@ -89,6 +89,10 @@ allow untrusted_app self:process ptrace; # for files. Suppress the denials when they occur. dontaudit untrusted_app exec_type:file getattr; +# TODO: access of /proc/meminfo, give specific label or switch to +# using meminfo service +allow untrusted_app proc:file r_file_perms; + ### ### neverallow rules ###