2019-12-24 10:11:02

by Jason Zaman

[permalink] [raw]
Subject: [PATCH 2/9] udev: Allow udevadm access to udev_tbl_t

From: Jason Zaman <[email protected]>

Signed-off-by: Jason Zaman <[email protected]>
---
policy/modules/system/udev.te | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/policy/modules/system/udev.te b/policy/modules/system/udev.te
index 31ae8915..faae587f 100644
--- a/policy/modules/system/udev.te
+++ b/policy/modules/system/udev.te
@@ -397,6 +397,10 @@ delete_lnk_files_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)
list_dirs_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)
read_files_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)

+list_dirs_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
+read_files_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
+read_lnk_files_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
+
dev_rw_sysfs(udevadm_t)
dev_read_urand(udevadm_t)

--
2.24.1


2019-12-26 17:30:03

by Chris PeBenito

[permalink] [raw]
Subject: Re: [PATCH 2/9] udev: Allow udevadm access to udev_tbl_t

On 12/24/19 5:10 AM, Jason Zaman wrote:
> From: Jason Zaman <[email protected]>
>
> Signed-off-by: Jason Zaman <[email protected]>
> ---
> policy/modules/system/udev.te | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/policy/modules/system/udev.te b/policy/modules/system/udev.te
> index 31ae8915..faae587f 100644
> --- a/policy/modules/system/udev.te
> +++ b/policy/modules/system/udev.te
> @@ -397,6 +397,10 @@ delete_lnk_files_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)
> list_dirs_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)
> read_files_pattern(udevadm_t, udev_runtime_t, udev_runtime_t)
>
> +list_dirs_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
> +read_files_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
> +read_lnk_files_pattern(udevadm_t, udev_tbl_t, udev_tbl_t)
> +
> dev_rw_sysfs(udevadm_t)
> dev_read_urand(udevadm_t)

Merged.

--
Chris PeBenito