From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Tue, 23 Aug 2011 15:39:13 +0200 Subject: [refpolicy] [PATCH 01/11] Introduce portage_dontaudit_use_fds In-Reply-To: <20110823133643.GA857@siphos.be> References: <20110823133643.GA857@siphos.be> Message-ID: <20110823133913.GB857@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Support the interface to not audit portage_t:fd use (file descriptors, leaked or not) Signed-off-by: Sven Vermeulen --- policy/modules/admin/portage.if | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/policy/modules/admin/portage.if b/policy/modules/admin/portage.if index 08b361b..a1bfbaa 100644 --- a/policy/modules/admin/portage.if +++ b/policy/modules/admin/portage.if @@ -293,3 +293,22 @@ interface(`portage_dontaudit_rw_tmp_files',` dontaudit $1 portage_tmp_t:file rw_file_perms; ') + +######################################## +## +## Do not audit attempts to use +## portage file descriptors. +## +## +## +## Domain to not audit. +## +## +# +interface(`portage_dontaudit_use_fds',` + gen_require(` + type portage_t; + ') + + dontaudit $1 portage_t:fds use; +') -- 1.7.3.4