From: dominick.grift@gmail.com (Dominick Grift) Date: Sun, 21 Oct 2012 14:20:13 +0200 Subject: [refpolicy] [PATCH 03/10] For svirt_lxc_domain In-Reply-To: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> References: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> Message-ID: <1350822019-15079-4-git-send-email-dominick.grift@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- policy/modules/kernel/files.if | 21 ++++++++++++++++++++- 1 files changed, 20 insertions(+), 1 deletions(-) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index d1e42ac..e188a21 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -2913,7 +2913,7 @@ interface(`files_delete_boot_flag',` ## ## ## -## Domain allowed access. +## Domain to not audit. ## ## # @@ -2927,6 +2927,25 @@ interface(`files_dontaudit_setattr_etc_runtime_files',` ######################################## ## +## Do not audit attempts to write +## etc runtime files. +## +## +## +## Domain to not audit. +## +## +# +interface(`files_dontaudit_write_etc_runtime_files',` + gen_require(` + type etc_runtime_t; + ') + + dontaudit $1 etc_runtime_t:file write; +') + +######################################## +## ## Read files in /etc that are dynamically ## created on boot, such as mtab. ## -- 1.7.7.6