diff --git a/debuggerd.te b/debuggerd.te index b85133b9da2a988adb89b73591f5e5f33aafa952..8ff37474c00158699034efa09c7ab3dcef8442fd 100644 --- a/debuggerd.te +++ b/debuggerd.te @@ -4,10 +4,14 @@ type debuggerd_exec, exec_type, file_type; init_daemon_domain(debuggerd) typeattribute debuggerd mlstrustedsubject; -allow debuggerd self:capability { dac_override sys_ptrace chown kill }; +allow debuggerd self:capability { dac_override sys_ptrace chown kill fowner }; allow debuggerd domain:dir r_dir_perms; allow debuggerd domain:file r_file_perms; allow debuggerd domain:process ptrace; +allow debuggerd rootfs:file r_file_perms; +allow debuggerd system_data_file:dir create_dir_perms; +allow debuggerd system_data_file:dir relabelfrom; +allow debuggerd tombstone_data_file:dir relabelto; allow debuggerd tombstone_data_file:dir create_dir_perms; allow debuggerd tombstone_data_file:file create_file_perms; allow debuggerd domain:process { sigstop signal };