From: gizmo@giz-works.com (Chris Richards) Date: Mon, 8 Nov 2010 19:25:33 -0600 Subject: [refpolicy] [PATCH 3/5] dontaudit mount writes to newly mounted filesystems In-Reply-To: <1289265935-2604-1-git-send-email-gizmo@giz-works.com> References: <1289265935-2604-1-git-send-email-gizmo@giz-works.com> Message-ID: <1289265935-2604-3-git-send-email-gizmo@giz-works.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Chris Richards --- policy/modules/kernel/filesystem.if | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if index 437a42a..b8714e5 100644 --- a/policy/modules/kernel/filesystem.if +++ b/policy/modules/kernel/filesystem.if @@ -3791,6 +3791,25 @@ interface(`fs_manage_tmpfs_dirs',` ######################################## ## +## Do not audit attempts to write +## tmpfs directories +## +## +## +## Domain allowed access. +## +## +# +interface(`fs_dontaudit_write_tmpfs_dirs',` + gen_require(` + type tmpfs_t; + ') + + dontaudit $1 tmpfs_t:dir write; +') + +######################################## +## ## Create an object in a tmpfs filesystem, with a private ## type using a type transition. ## -- 1.7.3.2