From 7c3e06881f84694dd2dd44de12cab8c47ba686c5 Mon Sep 17 00:00:00 2001 From: Logvinov Alecksey Date: Sun, 28 Jun 2020 20:31:33 +0300 Subject: [PATCH 1/3] =?UTF-8?q?=D0=98=D0=B7=D0=BC=D0=B5=D0=BD=D0=B8=D1=82?= =?UTF-8?q?=D1=8C=20'globus.te'?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- globus.te | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/globus.te b/globus.te index 310a828..895ef9e 100644 --- a/globus.te +++ b/globus.te @@ -13,13 +13,13 @@ require { type public_content_rw_t; type unreserved_port_t; class tcp_socket name_connect; - class dir { create rename reparent rmdir }; + class dir { add_name create rename reparent rmdir }; class file { append create execute execute_no_trans lock open read setattr unlink write }; } #============= httpd_t ============= allow httpd_t http_port_t:tcp_socket name_connect; -#allow httpd_t httpd_config_t:dir add_name; +allow httpd_t httpd_config_t:dir add_name; allow httpd_t httpd_config_t:file {append create}; allow httpd_t smtp_port_t:tcp_socket name_connect; From 8d82709b23dfbb34713b48ebd7e0d73b78c2c860 Mon Sep 17 00:00:00 2001 From: Logvinov Alecksey Date: Sun, 28 Jun 2020 20:37:02 +0300 Subject: [PATCH 2/3] =?UTF-8?q?=D0=98=D0=B7=D0=BC=D0=B5=D0=BD=D0=B8=D1=82?= =?UTF-8?q?=D1=8C=20'globus.te'?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- globus.te | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/globus.te b/globus.te index 895ef9e..1c3a2c5 100644 --- a/globus.te +++ b/globus.te @@ -33,4 +33,4 @@ allow init_t tmp_t:file unlink; allow init_t user_home_t:dir { create rename reparent rmdir }; allow init_t user_home_t:file { append create execute execute_no_trans lock open read setattr unlink write }; allow init_t public_content_rw_t:file execute; -allow init_t public_content_rw_t:file { append create execute open read setattr unlink write }; +allow init_t public_content_rw_t:file { append create execute execute_no_trans lock open read setattr unlink write }; From 85c713c9f40bd5885efb48f3c0f89798bfdff5f6 Mon Sep 17 00:00:00 2001 From: Logvinov Alecksey Date: Sun, 28 Jun 2020 21:20:15 +0300 Subject: [PATCH 3/3] =?UTF-8?q?=D0=98=D0=B7=D0=BC=D0=B5=D0=BD=D0=B8=D1=82?= =?UTF-8?q?=D1=8C=20'README.md'?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- README.md | 1 + 1 file changed, 1 insertion(+) diff --git a/README.md b/README.md index 6dbd3f6..74083b2 100644 --- a/README.md +++ b/README.md @@ -8,4 +8,5 @@ checkmodule -M -m -o globus.mod globus.te sudo semodule_package -o globus.pp -m globus.mod sudo semodule -i globus.pp rm -f globus.* +setsebool -P domain_can_mmap_files 1 ``` \ No newline at end of file