diff --git a/domain.te b/domain.te index 08aa4c1678a3a2b214ce5090dd8d2dd5bb1b70f0..06c0bddbcee2017bafdfb8e99dc1c57aad015800 100644 --- a/domain.te +++ b/domain.te @@ -146,6 +146,8 @@ r_dir_file(domain, sysfs_devices_system_cpu) r_dir_file(domain, inotify) r_dir_file(domain, cgroup) allow domain proc_cpuinfo:file r_file_perms; +allow domain proc_net:dir search; +allow domain proc_net_psched:file r_file_perms; # debugfs access allow domain debugfs:dir r_dir_perms; diff --git a/file.te b/file.te index e1de664c313fcdf783d8ef0df7c20da5f009c919..9ec6a20be7eb9dd6f91f70988ffc58220da5f9a7 100644 --- a/file.te +++ b/file.te @@ -12,6 +12,7 @@ type qtaguid_proc, fs_type, mlstrustedobject; type proc_bluetooth_writable, fs_type; type proc_cpuinfo, fs_type; type proc_net, fs_type; +type proc_net_psched, fs_type; type proc_sysrq, fs_type; type selinuxfs, fs_type, mlstrustedobject; type cgroup, fs_type, mlstrustedobject; diff --git a/genfs_contexts b/genfs_contexts index 31b7e4f6441fc06b450b3a6580eb1ff1eb6199c9..2f60ad1c50bc0462c5dfed4be154bafbfcadaf25 100644 --- a/genfs_contexts +++ b/genfs_contexts @@ -3,6 +3,7 @@ genfscon rootfs / u:object_r:rootfs:s0 # proc labeling can be further refined (longest matching prefix). genfscon proc / u:object_r:proc:s0 genfscon proc /net u:object_r:proc_net:s0 +genfscon proc /net/psched u:object_r:proc_net_psched:s0 genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0 genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0 genfscon proc /sysrq-trigger u:object_r:proc_sysrq:s0