From a473e29de0a5a1e88e1ac564d91dabb5437ae4fd Mon Sep 17 00:00:00 2001 From: Stephen Smalley <sds@tycho.nsa.gov> Date: Tue, 30 Jul 2013 09:19:00 -0400 Subject: [PATCH] write_klog also requires write permission to the directory. Signed-off-by: Stephen Smalley <sds@tycho.nsa.gov> --- te_macros | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/te_macros b/te_macros index 283c4a30c..931393824 100644 --- a/te_macros +++ b/te_macros @@ -303,7 +303,7 @@ allow $1 kernel:system syslog_read; define(`write_klog', ` type_transition $1 device:chr_file klog_device "__kmsg__"; allow $1 klog_device:chr_file { create open write unlink }; -allow $1 device:dir { add_name remove_name }; +allow $1 device:dir { write add_name remove_name }; ') ##################################### -- GitLab