From: dominick.grift@gmail.com (Dominick Grift) Date: Sun, 23 Sep 2012 17:15:40 +0200 Subject: [refpolicy] [PATCH v1 2/2] Implement files_create_all_files_as() for cachefilesd In-Reply-To: <1348413340-23536-1-git-send-email-dominick.grift@gmail.com> References: <1348413340-23536-1-git-send-email-dominick.grift@gmail.com> Message-ID: <1348413340-23536-3-git-send-email-dominick.grift@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- policy/modules/kernel/files.if | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index e1e814d..d1e42ac 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -1182,6 +1182,24 @@ interface(`files_list_all',` ######################################## ## +## Create all files as is. +## +## +## +## Domain allowed access. +## +## +# +interface(`files_create_all_files_as',` + gen_require(` + attribute file_type; + ') + + allow $1 file_type:kernel_service create_files_as; +') + +######################################## +## ## Do not audit attempts to search the ## contents of any directories on extended ## attribute filesystems. -- 1.7.11.4