From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Thu, 22 Mar 2012 21:06:57 +0100 Subject: [refpolicy] [PATCH 1/13] Adding dontaudit interfaces for files module In-Reply-To: <20120322200229.GA3387@siphos.be> References: <20120322200229.GA3387@siphos.be> Message-ID: <20120322200657.GB3387@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Sven Vermeulen --- policy/modules/kernel/files.if | 36 ++++++++++++++++++++++++++++++++++++ 1 files changed, 36 insertions(+), 0 deletions(-) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index deb24b4..7df46ac 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -1482,6 +1482,42 @@ interface(`files_dontaudit_list_all_mountpoints',` ######################################## ## +## Do not audit write attempts on mount points. +## +## +## +## Domain to ignore write attempts from +## +## +# +interface(`files_dontaudit_write_all_mountpoints',` + gen_require(` + attribute mountpoint; + ') + + dontaudit $1 mountpoint:dir write; +') + +######################################## +## +## Do not audit setattr attempts on mount points. +## +## +## +## Domain to ignore setattr attempts from +## +## +# +interface(`files_dontaudit_setattr_all_mountpoints',` + gen_require(` + attribute mountpoint; + ') + + dontaudit $1 mountpoint:dir setattr; +') + +######################################## +## ## List the contents of the root directory. ## ## -- 1.7.3.4