[refpolicy] [PATCH 6/13] Adding dontaudit interfaces in sysnet
Sven Vermeulen
sven.vermeulen at siphos.be
Thu Mar 22 15:10:13 CDT 2012
Signed-off-by: Sven Vermeulen <sven.vermeulen at siphos.be>
---
policy/modules/system/sysnetwork.if | 19 +++++++++++++++++++
1 files changed, 19 insertions(+), 0 deletions(-)
diff --git a/policy/modules/system/sysnetwork.if b/policy/modules/system/sysnetwork.if
index 363e98d..58a7d89 100644
--- a/policy/modules/system/sysnetwork.if
+++ b/policy/modules/system/sysnetwork.if
@@ -66,6 +66,25 @@ interface(`sysnet_dontaudit_use_dhcpc_fds',`
########################################
## <summary>
+## Do not audit attempts to read/write to the
+## dhcp unix stream socket descriptors.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain to not audit.
+## </summary>
+## </param>
+#
+interface(`sysnet_dontaudit_rw_dhcpc_unix_stream_sockets',`
+ gen_require(`
+ type dhcpc_t;
+ ')
+
+ dontaudit $1 dhcpc_t:unix_stream_socket { read write };
+')
+
+########################################
+## <summary>
## Send a SIGCHLD signal to the dhcp client.
## </summary>
## <param name="domain">
--
1.7.3.4
More information about the refpolicy
mailing list