Project

General

Profile

Actions

Feature #4113

open

Restrict Foreman not to be able to write to /usr/share/foreman

Added by Lukas Zapletal over 10 years ago. Updated almost 10 years ago.

Status:
New
Priority:
Low
Category:
-
Target version:
-
Difficulty:
Triaged:
Fixed in Releases:
Found in Releases:

Description

Currently Foreman is allowed to write to foreman_lib_t:

read_files_pattern(httpd_t, foreman_lib_t, foreman_lib_t)
manage_files_pattern(passenger_t, foreman_lib_t, foreman_lib_t)
manage_dirs_pattern(passenger_t, foreman_lib_t, foreman_lib_t)

We should tighten this and also make sure that public/avatar directory is in different domain (writable).

Actions

Also available in: Atom PDF