From: gizmo@giz-works.com (Chris Richards) Date: Mon, 8 Nov 2010 19:25:32 -0600 Subject: [refpolicy] [PATCH 2/5] dontaudit mount writes to newly mounted filesystems In-Reply-To: <1289265935-2604-1-git-send-email-gizmo@giz-works.com> References: <1289265935-2604-1-git-send-email-gizmo@giz-works.com> Message-ID: <1289265935-2604-2-git-send-email-gizmo@giz-works.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Chris Richards --- policy/modules/kernel/files.if | 20 +++++++++++++++++++- 1 files changed, 19 insertions(+), 1 deletions(-) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index 5302dac..8f69b85 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -1463,7 +1463,25 @@ interface(`files_list_root',` allow $1 root_t:lnk_file { read_lnk_file_perms ioctl lock }; ') -######################################## +############################################################# +## +## Do not audit attempts to write to / dirs. +## +## +## +## Domain to not audit. +## +## +# +interface(`files_dontaudit_write_root_dirs',` + gen_require(` + type root_t; + ') + + dontaudit $1 root_t:dir write; +') + +################### ## ## Do not audit attempts to write ## files in the root directory. -- 1.7.3.2