diff --git a/file.te b/file.te index 555b89fbf73d4b06cf0dedce9afaa5ab26d1373a..59a2cc5c08b369671d2db60d974526d7aaddf41b 100644 --- a/file.te +++ b/file.te @@ -13,6 +13,7 @@ type usermodehelper, fs_type, sysfs_type; type qtaguid_proc, fs_type, mlstrustedobject; type proc_bluetooth_writable, fs_type; type proc_cpuinfo, fs_type; +type proc_iomem, fs_type; type proc_net, fs_type; type proc_sysrq, fs_type; type proc_uid_cputime_showstat, fs_type; diff --git a/genfs_contexts b/genfs_contexts index cdf65bc63d54650130996f3e2853396579701500..3f865c4e4b7ed8203b34a924890cf96aa14f4f05 100644 --- a/genfs_contexts +++ b/genfs_contexts @@ -2,6 +2,7 @@ genfscon rootfs / u:object_r:rootfs:s0 # proc labeling can be further refined (longest matching prefix). genfscon proc / u:object_r:proc:s0 +genfscon proc /iomem u:object_r:proc_iomem:s0 genfscon proc /net u:object_r:proc_net:s0 genfscon proc /net/xt_qtaguid/ctrl u:object_r:qtaguid_proc:s0 genfscon proc /cpuinfo u:object_r:proc_cpuinfo:s0