From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Fri, 20 Apr 2012 16:12:25 -0400 Subject: [refpolicy] [PATCH 5/6] Adding dontaudit for qemu In-Reply-To: <20120322200931.GF3387@siphos.be> References: <20120322200229.GA3387@siphos.be> <20120322200931.GF3387@siphos.be> Message-ID: <4F91C329.1000909@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 03/22/12 16:09, Sven Vermeulen wrote: > > Signed-off-by: Sven Vermeulen > --- > qemu.te | 1 + > 1 files changed, 1 insertions(+), 0 deletions(-) > > diff --git a/qemu.te b/qemu.te > index 9cf9992..a75f91a 100644 > --- a/qemu.te > +++ b/qemu.te > @@ -49,6 +49,7 @@ role system_r types qemu_t; > # > # qemu local policy > # > +dontaudit qemu_t self:socket create; > > storage_raw_write_removable_device(qemu_t) > storage_raw_read_removable_device(qemu_t) I'm more interesting in finding out what kind of socket this is, so we can create an appropriate object class. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com