rss_hwm_reset.te 464 B

1234567891011121314
  1. type rss_hwm_reset_exec, system_file_type, exec_type, file_type;
  2. # Start rss_hwm_reset from init.
  3. init_daemon_domain(rss_hwm_reset)
  4. # Search /proc/pid directories.
  5. allow rss_hwm_reset domain:dir search;
  6. # Write to /proc/pid/clear_refs of other processes.
  7. # /proc/pid/clear_refs is S_IWUSER, see: fs/proc/base.c
  8. allow rss_hwm_reset self:global_capability_class_set { dac_override };
  9. # Write to /prc/pid/clear_refs.
  10. allow rss_hwm_reset domain:file w_file_perms;