linux-application-whitelisting / fapolicyd-selinux

selinux policy for fapolicyd daemon
7 stars 10 forks source link

Allow fapolicyd watch boot and home directories #9

Closed zpytela closed 3 years ago

zpytela commented 3 years ago

The fapolicyd service needs watch_mount and watch_with_perm permissions for fanotify/inotify/dnotify calls on the following directories:

Note the /boot/efi directory has the dosfs_t label.