From 9c91b908e1cd280c7376c4cdc1d3b56664f277e9 Mon Sep 17 00:00:00 2001 From: Vit Mojzis Date: Thu, 4 Jan 2024 17:15:39 +0100 Subject: [PATCH] SELinux: rename ifconfig_run interfaces to be more specific The change has no functional impact on the policy. It is just to keep it in sync with the interfaces shipped in selinux-policy-* packages. Signed-off-by: Vit Mojzis --- frr.if | 9 ++++----- frr.te | 4 ++-- 2 files changed, 6 insertions(+), 7 deletions(-) diff --git a/frr.if b/frr.if index d30c0bb..b68899a 100644 --- a/frr.if +++ b/frr.if @@ -181,8 +181,8 @@ interface(`frr_admin',` ## ## # -ifndef(`sysnet_watch_ifconfig_run',` - interface(`sysnet_watch_ifconfig_run',` +ifndef(`sysnet_watch_ifconfig_run_dirs',` + interface(`sysnet_watch_ifconfig_run_dirs',` gen_require(` type ifconfig_var_run_t; ') @@ -201,8 +201,8 @@ ifndef(`sysnet_watch_ifconfig_run',` ## ## # -ifndef(`sysnet_read_ifconfig_run',` - interface(`sysnet_read_ifconfig_run',` +ifndef(`sysnet_read_ifconfig_run_files',` + interface(`sysnet_read_ifconfig_run_files',` gen_require(` type ifconfig_var_run_t; ') @@ -212,4 +212,3 @@ ifndef(`sysnet_read_ifconfig_run',` read_lnk_files_pattern($1, ifconfig_var_run_t, ifconfig_var_run_t) ') ') - diff --git a/frr.te b/frr.te index 47c064f..13ed9ac 100644 --- a/frr.te +++ b/frr.te @@ -98,8 +98,8 @@ domain_use_interactive_fds(frr_t) fs_read_nsfs_files(frr_t) sysnet_exec_ifconfig(frr_t) -sysnet_read_ifconfig_run(frr_t) -sysnet_watch_ifconfig_run(frr_t) +sysnet_read_ifconfig_run_files(frr_t) +sysnet_watch_ifconfig_run_dirs(frr_t) ipsec_domtrans_mgmt(frr_t)