[refpolicy] [PATCH 1/13] Adding dontaudit interfaces for files module

Sven Vermeulen sven.vermeulen at siphos.be
Thu Mar 22 15:06:57 CDT 2012


Signed-off-by: Sven Vermeulen <sven.vermeulen at siphos.be>
---
 policy/modules/kernel/files.if |   36 ++++++++++++++++++++++++++++++++++++
 1 files changed, 36 insertions(+), 0 deletions(-)

diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if
index deb24b4..7df46ac 100644
--- a/policy/modules/kernel/files.if
+++ b/policy/modules/kernel/files.if
@@ -1482,6 +1482,42 @@ interface(`files_dontaudit_list_all_mountpoints',`
 
 ########################################
 ## <summary>
+##     Do not audit write attempts on mount points.
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain to ignore write attempts from
+##     </summary>
+## </param>
+#
+interface(`files_dontaudit_write_all_mountpoints',`
+	gen_require(`
+		attribute mountpoint;
+	')
+       
+	dontaudit $1 mountpoint:dir write;
+')     
+
+########################################
+## <summary>
+##     Do not audit setattr attempts on mount points.
+## </summary>
+## <param name="domain">
+##     <summary>
+##     Domain to ignore setattr attempts from
+##     </summary>
+## </param>
+#
+interface(`files_dontaudit_setattr_all_mountpoints',`
+	gen_require(`
+		attribute mountpoint;
+	')
+
+	dontaudit $1 mountpoint:dir setattr;
+')
+
+########################################
+## <summary>
 ##	List the contents of the root directory.
 ## </summary>
 ## <param name="domain">
-- 
1.7.3.4



More information about the refpolicy mailing list