[refpolicy] Interface naming question for a filetrans

Sven Vermeulen sven.vermeulen at siphos.be
Sun Jul 1 04:29:20 CDT 2012

Hi guys,

Let's say I am in the need for two interfaces.

One would do:
  files_pid_filetrans($1, udev_rules_t, dir, $2)
the other one
  filetrans_pattern($1, udev_var_run_t, udev_rules_t, dir, $2)

I'm a bit in doubt about what to call the interfaces.

I believe the first one would be "udev_pid_filetrans_rules_dirs" as it seems
that all *_pid_filetrans routines I find in the policy are about the
var_run_t-based file transition, but then for the second one we would have
no clear answer.

One way to tackle such cases, as Dominick Grift suggested on the chat, is to
use *_generic_pid_filetrans for all the files_pid_filetrans() interfaces
currently in the policy, but that does mean all interfaces will need to be

Then udev_generic_pid_filetrans_rules_dirs could be used for the first case,
and udev_pid_filetrans_rules_dirs for the second.

So, what's the take on this?

	Sven Vermeulen

More information about the refpolicy mailing list