ec2-instance-connect/ec2-instance-connect.te
Fedora Release Engineering 57dde6752a Unretire package: ec2-instance-connect on rawhide
Reverts retirement commit 17387736e1
Releng issue: https://pagure.io/releng/issue/12836
2025-07-23 18:50:51 +00:00

18 lines
491 B
Text

module ec2-instance-connect 1.0;
require {
type ssh_keygen_exec_t;
type sshd_t;
type http_port_t;
class file { execute execute_no_trans open read };
class process setpgid;
class tcp_socket name_connect;
class file map;
}
#============= sshd_t ==============
allow sshd_t http_port_t:tcp_socket name_connect;
allow sshd_t self:process setpgid;
allow sshd_t ssh_keygen_exec_t:file { execute execute_no_trans open read };
allow sshd_t ssh_keygen_exec_t:file map;