Skip to content
Open

games #1026

Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions policy/modules/apps/games.te
Original file line number Diff line number Diff line change
Expand Up @@ -92,7 +92,9 @@ optional_policy(`
allow games_t self:fifo_file rw_fifo_file_perms;
allow games_t self:sem create_sem_perms;
allow games_t self:tcp_socket { accept listen };
allow games_t self:process getsched;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please move up to line 91.


manage_dirs_pattern(games_t, games_data_t, games_data_t)
manage_files_pattern(games_t, games_data_t, games_data_t)
manage_lnk_files_pattern(games_t, games_data_t, games_data_t)

Expand All @@ -101,6 +103,8 @@ term_create_pty(games_t, games_devpts_t)

manage_dirs_pattern(games_t, games_tmp_t, games_tmp_t)
manage_files_pattern(games_t, games_tmp_t, games_tmp_t)
allow games_t games_tmp_t:file map;
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

mmap_manage_files_pattern


files_tmp_filetrans(games_t, games_tmp_t, { file dir })

manage_files_pattern(games_t, games_tmpfs_t, games_tmpfs_t)
Expand Down Expand Up @@ -128,6 +132,8 @@ corenet_tcp_bind_generic_port(games_t)
corenet_sendrecv_generic_client_packets(games_t)
corenet_tcp_connect_generic_port(games_t)

corenet_udp_bind_generic_node(games_t)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

There isn't a udp bind for port(s).


dev_read_sound(games_t)
dev_read_input(games_t)
dev_read_mouse(games_t)
Expand All @@ -136,13 +142,16 @@ dev_rw_dri(games_t)
dev_write_sound(games_t)

files_list_var(games_t)
files_search_mnt(games_t)
files_search_var_lib(games_t)
files_dontaudit_search_var(games_t)
files_map_usr_files(games_t)
files_read_etc_files(games_t)
files_read_usr_files(games_t)
files_read_var_files(games_t)

fs_dontaudit_getattr_xattr_fs(games_t)
fs_search_nfs(games_t)

init_dontaudit_rw_utmp(games_t)

Expand All @@ -158,6 +167,7 @@ userdom_manage_user_tmp_dirs(games_t)
userdom_manage_user_tmp_files(games_t)
userdom_manage_user_tmp_symlinks(games_t)
userdom_manage_user_tmp_sockets(games_t)
userdom_use_user_ptys(games_t)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please use userdom_use_inherited_user_terminals().

userdom_dontaudit_read_user_home_content_files(games_t)

tunable_policy(`allow_execmem',`
Expand All @@ -166,6 +176,7 @@ tunable_policy(`allow_execmem',`

optional_policy(`
alsa_read_config(games_t)
alsa_read_home_files(games_t)
')

optional_policy(`
Expand Down
Loading