From a473e29de0a5a1e88e1ac564d91dabb5437ae4fd Mon Sep 17 00:00:00 2001
From: Stephen Smalley <sds@tycho.nsa.gov>
Date: Tue, 30 Jul 2013 09:19:00 -0400
Subject: [PATCH] write_klog also requires write permission to the directory.

Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov>
---
 te_macros | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/te_macros b/te_macros
index 283c4a30c..931393824 100644
--- a/te_macros
+++ b/te_macros
@@ -303,7 +303,7 @@ allow $1 kernel:system syslog_read;
 define(`write_klog', `
 type_transition $1 device:chr_file klog_device "__kmsg__";
 allow $1 klog_device:chr_file { create open write unlink };
-allow $1 device:dir { add_name remove_name };
+allow $1 device:dir { write add_name remove_name };
 ')
 
 #####################################
-- 
GitLab