aboutgitcodebugslistschat
path: root/contrib
diff options
context:
space:
mode:
authorStefano Brivio <sbrivio@redhat.com>2023-08-15 18:34:45 +0200
committerStefano Brivio <sbrivio@redhat.com>2023-08-18 13:18:45 +0200
commit0c42326204c1b8ece86512d9d5014d8603449430 (patch)
tree9774355400e0eaaae8c7a1afae7843a86d344e7d /contrib
parent479a9e1b4d9b4e426754b44fb767d252ca144e0f (diff)
downloadpasst-0c42326204c1b8ece86512d9d5014d8603449430.tar
passt-0c42326204c1b8ece86512d9d5014d8603449430.tar.gz
passt-0c42326204c1b8ece86512d9d5014d8603449430.tar.bz2
passt-0c42326204c1b8ece86512d9d5014d8603449430.tar.lz
passt-0c42326204c1b8ece86512d9d5014d8603449430.tar.xz
passt-0c42326204c1b8ece86512d9d5014d8603449430.tar.zst
passt-0c42326204c1b8ece86512d9d5014d8603449430.zip
selinux: Use explicit paths for binaries in file context
There's no reason to use wildcards, and we don't want any similarly-named binary (not that I'm aware of any) to risk being associated to passt_exec_t and pasta_exec_t by accident. Signed-off-by: Stefano Brivio <sbrivio@redhat.com> Reviewed-by: Richard W.M. Jones <rjones@redhat.com>
Diffstat (limited to 'contrib')
-rw-r--r--contrib/selinux/passt.fc3
-rw-r--r--contrib/selinux/pasta.fc3
2 files changed, 4 insertions, 2 deletions
diff --git a/contrib/selinux/passt.fc b/contrib/selinux/passt.fc
index fb5b5d4..09bcaab 100644
--- a/contrib/selinux/passt.fc
+++ b/contrib/selinux/passt.fc
@@ -8,5 +8,6 @@
# Copyright (c) 2022 Red Hat GmbH
# Author: Stefano Brivio <sbrivio@redhat.com>
-/usr/bin/passt(\.*)? system_u:object_r:passt_exec_t:s0
+/usr/bin/passt system_u:object_r:passt_exec_t:s0
+/usr/bin/passt.avx2 system_u:object_r:passt_exec_t:s0
/tmp/passt\.pcap system_u:object_r:passt_log_t:s0
diff --git a/contrib/selinux/pasta.fc b/contrib/selinux/pasta.fc
index 2ffb41a..41ee46d 100644
--- a/contrib/selinux/pasta.fc
+++ b/contrib/selinux/pasta.fc
@@ -8,6 +8,7 @@
# Copyright (c) 2022 Red Hat GmbH
# Author: Stefano Brivio <sbrivio@redhat.com>
-/usr/bin/pasta(\.*)? system_u:object_r:pasta_exec_t:s0
+/usr/bin/pasta system_u:object_r:pasta_exec_t:s0
+/usr/bin/pasta.avx2 system_u:object_r:pasta_exec_t:s0
/tmp/pasta\.pcap system_u:object_r:pasta_log_t:s0
/var/run/pasta\.pid system_u:object_r:pasta_pid_t:s0