From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Wed, 20 Jul 2011 17:19:49 +0200 Subject: [refpolicy] [PATCH 2/4] Adding haveged IF definition In-Reply-To: <20110720151732.GA18841@siphos.be> References: <20110720151732.GA18841@siphos.be> Message-ID: <20110720151949.GC18841@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Define the administrative interface so that domains can manage the haveged processes. Signed-off-by: Sven Vermeulen --- policy/modules/services/haveged.if | 26 ++++++++++++++++++++++++++ 1 files changed, 26 insertions(+), 0 deletions(-) create mode 100644 policy/modules/services/haveged.if diff --git a/policy/modules/services/haveged.if b/policy/modules/services/haveged.if new file mode 100644 index 0000000..4bb8f4f --- /dev/null +++ b/policy/modules/services/haveged.if @@ -0,0 +1,26 @@ +## Haveged service + +######################################## +## +## Administer haveged +## +## +## +## Domain allowed access. +## +## +## +## +## The role to be allowed to manage the haveged domain. +## +## +## +# +interface(`haveged_admin',` + gen_require(` + type haveged_t; + ') + + allow $1 haveged_t:process { ptrace signal_perms }; + ps_process_pattern($1, haveged_t) +') -- 1.7.3.4