diff --git a/private/genfs_contexts b/private/genfs_contexts index 0c506757984df104d779fd39ceabcb1d63f01f7a..d1e1b91f2cfb93466291dfc97a76c8173a0faa2a 100644 --- a/private/genfs_contexts +++ b/private/genfs_contexts @@ -26,6 +26,8 @@ genfscon proc /sys/kernel/randomize_va_space u:object_r:proc_security:s0 genfscon proc /sys/kernel/usermodehelper u:object_r:usermodehelper:s0 genfscon proc /sys/net u:object_r:proc_net:s0 genfscon proc /sys/vm/mmap_min_addr u:object_r:proc_security:s0 +genfscon proc /sys/vm/mmap_rnd_bits u:object_r:proc_security:s0 +genfscon proc /sys/vm/mmap_rnd_compat_bits u:object_r:proc_security:s0 genfscon proc /sys/vm/drop_caches u:object_r:proc_drop_caches:s0 genfscon proc /sys/vm/overcommit_memory u:object_r:proc_overcommit_memory:s0 genfscon proc /timer_list u:object_r:proc_timer:s0 diff --git a/public/domain.te b/public/domain.te index e2c71da6165666d9fb63a719457c9a6490bf24f1..10e62b82af904dbeb542a35eaf1eec8a16125fdc 100644 --- a/public/domain.te +++ b/public/domain.te @@ -251,7 +251,7 @@ neverallow * port_device:chr_file ~{ create relabelto unlink setattr getattr }; # Only init should be able to configure kernel usermodehelpers or # security-sensitive proc settings. neverallow { domain -init } usermodehelper:file { append write }; -neverallow { domain -init } proc_security:file { append write }; +neverallow { domain -init } proc_security:file { append open read write }; # No domain should be allowed to ptrace init. neverallow * init:process ptrace;