From Debian package 0.0.20080702-4 Add files_manage_pid_dirs interface - unused Lacks read_lnk_file_perms for symlink to /run Index: policy/modules/kernel/files.if =================================================================== --- policy/modules/kernel/files.if.orig +++ policy/modules/kernel/files.if @@ -5822,6 +5822,25 @@ ######################################## ## +## Create directories under /var/run +## +## +## +## Domain allowed access. +## +## +# +interface(`files_manage_pid_dirs',` + gen_require(` + type var_t, var_run_t; + ') + + allow $1 var_t:dir search; + allow $1 var_run_t:dir manage_dir_perms; +') + +######################################## +## ## Do not audit attempts to write to daemon runtime data files. ## ##