linux-application-whitelisting / fapolicyd-selinux

selinux policy for fapolicyd daemon
7 stars 10 forks source link

Allow fapolicyd fs_watch_with_perm and fs_watch_mount tmpfs dirs #5

Closed zpytela closed 3 years ago

zpytela commented 3 years ago

New watch permissions have been introduced info selinux-policy. The fapolicyd daemon needs watch permissions for inotify calls on tmpfs directories.

zpytela commented 3 years ago

Note this commit needs the new permissions merged in selinux-policy which should take place today.