CBL-Mariner/SPECS/selinux-policy/0021-files-Handle-symlinks-...

37 строки
1.2 KiB
Diff

From fbf606a8a0a7bb13a0a55d0c406bcac9467cb29b Mon Sep 17 00:00:00 2001
From: Chris PeBenito <Christopher.PeBenito@microsoft.com>
Date: Wed, 8 Feb 2023 18:31:59 +0000
Subject: [PATCH 21/35] files: Handle symlinks for /media and /srv.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com>
---
policy/modules/kernel/files.fc | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
MSFT_TAG: pending
diff --git a/policy/modules/kernel/files.fc b/policy/modules/kernel/files.fc
index f6ff6b079..0a72dd356 100644
--- a/policy/modules/kernel/files.fc
+++ b/policy/modules/kernel/files.fc
@@ -110,7 +110,7 @@ HOME_ROOT/lost\+found/.* <<none>>
#
# Mount points; do not relabel subdirectories, since
# we don't want to change any removable media by default.
-/media(/[^/]*) -l gen_context(system_u:object_r:mnt_t,s0)
+/media(/[^/]*)? -l gen_context(system_u:object_r:mnt_t,s0)
/media(/[^/]*)? -d gen_context(system_u:object_r:mnt_t,s0)
/media/[^/]*/.* <<none>>
/media/\.hal-.* -- gen_context(system_u:object_r:mnt_t,s0)
@@ -164,6 +164,7 @@ HOME_ROOT/lost\+found/.* <<none>>
# /srv
#
/srv -d gen_context(system_u:object_r:var_t,s0)
+/srv -l gen_context(system_u:object_r:var_t,s0)
/srv/.* gen_context(system_u:object_r:var_t,s0)
#
--
2.34.1