unconfined.fc 1.1 KB

123456789101112131415161718192021
  1. # Add programs here which should not be confined by SELinux
  2. # e.g.:
  3. # /usr/local/bin/appsrv -- gen_context(system_u:object_r:unconfined_exec_t,s0)
  4. # For the time being until someone writes a sane policy, we need initrc to transition to unconfined_t
  5. /usr/bin/valgrind -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  6. /usr/bin/vncserver -- gen_context(system_u:object_r:unconfined_exec_t,s0)
  7. /usr/lib/ia32el/ia32x_loader -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  8. /usr/lib/openoffice\.org.*/program/.+\.bin -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  9. /usr/local/RealPlayer/realplay\.bin -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  10. ifdef(`distro_debian',`
  11. /usr/bin/gcj-dbtool-4\.1 -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  12. /usr/bin/gij-4\.1 -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  13. /usr/lib/openoffice/program/soffice\.bin -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  14. ')
  15. ifdef(`distro_gentoo',`
  16. /usr/lib/openoffice/program/[^/]+\.bin -- gen_context(system_u:object_r:unconfined_execmem_exec_t,s0)
  17. ')