2012-10-30 18:39:44

by dominick.grift

[permalink] [raw]
Subject: [refpolicy] [PATCH 10/10] For virtd

Signed-off-by: Dominick Grift <[email protected]>
---
policy/modules/kernel/devices.if | 18 ++++++++++++++++++
1 files changed, 18 insertions(+), 0 deletions(-)

diff --git a/policy/modules/kernel/devices.if b/policy/modules/kernel/devices.if
index e59415f..9b9c067 100644
--- a/policy/modules/kernel/devices.if
+++ b/policy/modules/kernel/devices.if
@@ -4167,6 +4167,24 @@ interface(`dev_read_generic_usb_dev',`

########################################
## <summary>
+## Relabel generic the USB devices.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`dev_relabel_generic_usb_dev',`
+ gen_require(`
+ type usb_device_t;
+ ')
+
+ relabel_chr_files_pattern($1, device_t, usb_device_t)
+')
+
+########################################
+## <summary>
## Read and write generic the USB devices.
## </summary>
## <param name="domain">
--
1.7.7.6


2012-10-30 20:00:37

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [PATCH 10/10] For virtd

On 10/30/12 14:39, Dominick Grift wrote:
> Signed-off-by: Dominick Grift <[email protected]>
> ---
> policy/modules/kernel/devices.if | 18 ++++++++++++++++++
> 1 files changed, 18 insertions(+), 0 deletions(-)
>
> diff --git a/policy/modules/kernel/devices.if b/policy/modules/kernel/devices.if
> index e59415f..9b9c067 100644
> --- a/policy/modules/kernel/devices.if
> +++ b/policy/modules/kernel/devices.if
> @@ -4167,6 +4167,24 @@ interface(`dev_read_generic_usb_dev',`
>
> ########################################
> ## <summary>
> +## Relabel generic the USB devices.
> +## </summary>
> +## <param name="domain">
> +## <summary>
> +## Domain allowed access.
> +## </summary>
> +## </param>
> +#
> +interface(`dev_relabel_generic_usb_dev',`
> + gen_require(`
> + type usb_device_t;
> + ')
> +
> + relabel_chr_files_pattern($1, device_t, usb_device_t)
> +')
> +
> +########################################
> +## <summary>
> ## Read and write generic the USB devices.
> ## </summary>
> ## <param name="domain">

Merged.

--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com