aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Göttsche <cgzones@googlemail.com>2024-02-22 18:00:33 +0100
committerKenton Groombridge <concord@gentoo.org>2024-03-01 12:05:43 -0500
commit6d1c3e8b33d3134dbe1767539363491a5f1600ea (patch)
treebd2ee87724ceae6a20940f794aa13eaeb7fce0a6
parentMakefile: set PYTHONPATH for test toolchain (diff)
downloadhardened-refpolicy-6d1c3e8b33d3134dbe1767539363491a5f1600ea.tar.gz
hardened-refpolicy-6d1c3e8b33d3134dbe1767539363491a5f1600ea.tar.bz2
hardened-refpolicy-6d1c3e8b33d3134dbe1767539363491a5f1600ea.zip
virt: label qemu configuration directory
Signed-off-by: Christian Göttsche <cgzones@googlemail.com> Signed-off-by: Kenton Groombridge <concord@gentoo.org>
-rw-r--r--policy/modules/services/virt.fc2
1 files changed, 2 insertions, 0 deletions
diff --git a/policy/modules/services/virt.fc b/policy/modules/services/virt.fc
index ab5d0885d..9c209d8f0 100644
--- a/policy/modules/services/virt.fc
+++ b/policy/modules/services/virt.fc
@@ -9,6 +9,8 @@ HOME_DIR/VirtualMachines/isos(/.*)? gen_context(system_u:object_r:virt_content_t
/etc/libvirt/[^/]* -d gen_context(system_u:object_r:virt_etc_rw_t,s0)
/etc/libvirt/.*/.* gen_context(system_u:object_r:virt_etc_rw_t,s0)
+/etc/qemu(/.*)? gen_context(system_u:object_r:virt_etc_t,s0)
+
/etc/rc\.d/init\.d/(libvirt-bin|libvirtd) -- gen_context(system_u:object_r:virtd_initrc_exec_t,s0)
/etc/xen -d gen_context(system_u:object_r:virt_etc_t,s0)