diff --git a/untrusted_app.te b/untrusted_app.te index dff1cb28e65c5cad8c36ce1c64612c24a03a224e..333f1f4af2539a0c217f131f56800073a81fa36c 100644 --- a/untrusted_app.te +++ b/untrusted_app.te @@ -94,6 +94,8 @@ dontaudit untrusted_app exec_type:file getattr; # TODO: access of /proc/meminfo, give specific label or switch to # using meminfo service allow untrusted_app proc:file r_file_perms; +# access /proc/net/xt_qtguid/stats +r_dir_file(untrusted_app, proc_net) ### ### neverallow rules