aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <chpebeni@linux.microsoft.com>2023-10-02 08:44:00 -0400
committerKenton Groombridge <concord@gentoo.org>2023-10-06 11:31:45 -0400
commit6f8208d24c132738f65741594de5b1b3b11d1a9c (patch)
tree8def983d31d903c12d6a84d1a6bf19c6b54f28b6
parentbind: fix for named service (diff)
downloadhardened-refpolicy-6f8208d24c132738f65741594de5b1b3b11d1a9c.tar.gz
hardened-refpolicy-6f8208d24c132738f65741594de5b1b3b11d1a9c.tar.bz2
hardened-refpolicy-6f8208d24c132738f65741594de5b1b3b11d1a9c.zip
Add append to rw and manage lnk_file permission sets for consistency.
Signed-off-by: Chris PeBenito <chpebeni@linux.microsoft.com> Signed-off-by: Kenton Groombridge <concord@gentoo.org>
-rw-r--r--policy/support/obj_perm_sets.spt4
1 files changed, 2 insertions, 2 deletions
diff --git a/policy/support/obj_perm_sets.spt b/policy/support/obj_perm_sets.spt
index d1784fae1..4b2b7c874 100644
--- a/policy/support/obj_perm_sets.spt
+++ b/policy/support/obj_perm_sets.spt
@@ -181,11 +181,11 @@ define(`setattr_lnk_file_perms',`{ setattr }')
define(`read_lnk_file_perms',`{ getattr read }')
define(`append_lnk_file_perms',`{ getattr append lock ioctl }')
define(`write_lnk_file_perms',`{ getattr append write lock ioctl }')
-define(`rw_lnk_file_perms',`{ getattr read write lock ioctl }')
+define(`rw_lnk_file_perms',`{ getattr read write append lock ioctl }')
define(`create_lnk_file_perms',`{ create getattr }')
define(`rename_lnk_file_perms',`{ getattr rename }')
define(`delete_lnk_file_perms',`{ getattr unlink }')
-define(`manage_lnk_file_perms',`{ create read write getattr setattr link unlink rename ioctl lock }')
+define(`manage_lnk_file_perms',`{ create read write append getattr setattr link unlink rename ioctl lock }')
define(`relabelfrom_lnk_file_perms',`{ getattr relabelfrom }')
define(`relabelto_lnk_file_perms',`{ getattr relabelto }')
define(`relabel_lnk_file_perms',`{ getattr relabelfrom relabelto }')