From: dominick.grift@gmail.com (Dominick Grift) Date: Wed, 17 Oct 2012 14:29:18 +0200 Subject: [refpolicy] [PATCH] Changes to the kernel policy module Message-ID: <1350476958-5883-1-git-send-email-dominick.grift@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Interface is needed by at least plymouth Signed-off-by: Dominick Grift diff --git a/policy/modules/kernel/kernel.if b/policy/modules/kernel/kernel.if index 4bf45cb..7cbf5d6 100644 --- a/policy/modules/kernel/kernel.if +++ b/policy/modules/kernel/kernel.if @@ -565,6 +565,25 @@ ######################################## ## +## Connect to kernel using a unix +## domain stream socket. +## +## +## +## Domain allowed access. +## +## +# +interface(`kernel_stream_connect',` + gen_require(` + type kernel_t; + ') + + allow $1 kernel_t:unix_stream_socket connectto; +') + +######################################## +## ## Get information on all System V IPC objects. ## ##