etc: SELinux: Label guix-daemon executable in profile.
authorRicardo Wurmus <rekado@elephly.net>
Fri, 23 Dec 2022 15:44:58 +0000 (16:44 +0100)
committerRicardo Wurmus <rekado@elephly.net>
Fri, 23 Dec 2022 19:20:06 +0000 (20:20 +0100)
* etc/guix-daemon.cil.in: Add file rule for "guix-daemon" in current-guix
profile.

etc/guix-daemon.cil.in

index f4767ff..ba100a4 100644 (file)
            any (unconfined_u object_r guix_store_content_t (low low)))
   (filecon "@prefix@/bin/guix-daemon"
            file (system_u object_r guix_daemon_exec_t (low low)))
+  (filecon "@guix_localstatedir@/guix/profiles/per-user/[^/]+/current-guix/bin/guix-daemon"
+           file (system_u object_r guix_daemon_exec_t (low low)))
   (filecon "@storedir@/.+-(guix-.+|profile)/bin/guix-daemon"
            file (system_u object_r guix_daemon_exec_t (low low)))
   (filecon "@storedir@/[a-z0-9]+-guix-daemon"