From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Thu, 22 Mar 2012 21:10:13 +0100 Subject: [refpolicy] [PATCH 6/13] Adding dontaudit interfaces in sysnet In-Reply-To: <20120322200229.GA3387@siphos.be> References: <20120322200229.GA3387@siphos.be> Message-ID: <20120322201013.GG3387@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Sven Vermeulen --- policy/modules/system/sysnetwork.if | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/policy/modules/system/sysnetwork.if b/policy/modules/system/sysnetwork.if index 363e98d..58a7d89 100644 --- a/policy/modules/system/sysnetwork.if +++ b/policy/modules/system/sysnetwork.if @@ -66,6 +66,25 @@ interface(`sysnet_dontaudit_use_dhcpc_fds',` ######################################## ## +## Do not audit attempts to read/write to the +## dhcp unix stream socket descriptors. +## +## +## +## Domain to not audit. +## +## +# +interface(`sysnet_dontaudit_rw_dhcpc_unix_stream_sockets',` + gen_require(` + type dhcpc_t; + ') + + dontaudit $1 dhcpc_t:unix_stream_socket { read write }; +') + +######################################## +## ## Send a SIGCHLD signal to the dhcp client. ## ## -- 1.7.3.4