Skip to content
Snippets Groups Projects
Commit 5f9917c1 authored by Stephen Smalley's avatar Stephen Smalley
Browse files

Allow debuggerd to restorecon the tombstone directory.

parent 901cc366
No related branches found
No related tags found
No related merge requests found
...@@ -4,10 +4,14 @@ type debuggerd_exec, exec_type, file_type; ...@@ -4,10 +4,14 @@ type debuggerd_exec, exec_type, file_type;
init_daemon_domain(debuggerd) init_daemon_domain(debuggerd)
typeattribute debuggerd mlstrustedsubject; typeattribute debuggerd mlstrustedsubject;
allow debuggerd self:capability { dac_override sys_ptrace chown kill }; allow debuggerd self:capability { dac_override sys_ptrace chown kill fowner };
allow debuggerd domain:dir r_dir_perms; allow debuggerd domain:dir r_dir_perms;
allow debuggerd domain:file r_file_perms; allow debuggerd domain:file r_file_perms;
allow debuggerd domain:process ptrace; allow debuggerd domain:process ptrace;
allow debuggerd rootfs:file r_file_perms;
allow debuggerd system_data_file:dir create_dir_perms;
allow debuggerd system_data_file:dir relabelfrom;
allow debuggerd tombstone_data_file:dir relabelto;
allow debuggerd tombstone_data_file:dir create_dir_perms; allow debuggerd tombstone_data_file:dir create_dir_perms;
allow debuggerd tombstone_data_file:file create_file_perms; allow debuggerd tombstone_data_file:file create_file_perms;
allow debuggerd domain:process { sigstop signal }; allow debuggerd domain:process { sigstop signal };
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment