diff --git a/tee.te b/tee.te index 1aae06ea0373b04cdcb4717145a379d2edda4702..c612821d4b61aa43ed45863fdb40a964b7879213 100644 --- a/tee.te +++ b/tee.te @@ -2,9 +2,14 @@ # trusted execution environment (tee) daemon # type tee, domain; +permissive tee; type tee_exec, exec_type, file_type; type tee_device, dev_type; type tee_data_file, file_type, data_file_type; -unconfined_domain(tee) init_daemon_domain(tee) +allow tee self:capability { dac_override }; +allow tee tee_device:chr_file rw_file_perms; +allow tee tee_data_file:dir rw_dir_perms; +allow tee tee_data_file:file create_file_perms; +allow tee self:netlink_socket { create bind read };