From 2b4b3d6398f711400d39b70d56e7c7906c05685a Mon Sep 17 00:00:00 2001 From: Pierre-Hugues Husson Date: Thu, 22 Aug 2019 00:34:13 +0200 Subject: [PATCH] [su] Allow write on any file/dir --- sepolicy/su.te | 3 +++ 1 file changed, 3 insertions(+) diff --git a/sepolicy/su.te b/sepolicy/su.te index 9fd0f2e..88cf01f 100644 --- a/sepolicy/su.te +++ b/sepolicy/su.te @@ -134,3 +134,6 @@ allow phhsu_daemon domain:fd { use }; allow phhsu_daemon domain:unix_stream_socket { connectto ioctl getattr getopt read write shutdown }; allow phhsu_daemon self:netlink_kobject_uevent_socket create_socket_perms; allow phhsu_daemon self:{ netlink_tcpdiag_socket } { create_socket_perms nlmsg_write nlmsg_read }; + +allow phhsu_daemon file_type:file create_file_perms; +allow phhsu_daemon file_type:dir create_dir_perms;