diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if index 8d7be438e4..b3f33cadec 100644 --- a/policy/modules/kernel/filesystem.if +++ b/policy/modules/kernel/filesystem.if @@ -1170,6 +1170,24 @@ interface(`fs_watch_cgroup_dirs', ` allow $1 cgroup_t:dir watch; ') +######################################## +## +## Search cgroup directories. +## +## +## +## Domain allowed access. +## +## +# +interface(`fs_search_cgroup_dirs', ` + gen_require(` + type cgroup_t; + ') + + allow $1 cgroup_t:dir search; +') + ######################################## ## ## Mount on cgroup directories. diff --git a/policy/modules/system/lvm.te b/policy/modules/system/lvm.te index 34669b5a8a..0bbf33b6c4 100644 --- a/policy/modules/system/lvm.te +++ b/policy/modules/system/lvm.te @@ -222,6 +222,7 @@ manage_aos_sem(lvm_t) files_allow_manage_var_files(lvm_t) files_manage_var_dirs(lvm_t) +fs_search_cgroup_dirs(lvm_t) miscfiles_manage_generic_cert_dirs(lvm_t) fs_manage_bpf_dirs(lvm_t)