From: dominick.grift@gmail.com (Dominick Grift) Date: Sun, 21 Oct 2012 14:20:14 +0200 Subject: [refpolicy] [PATCH 04/10] For virtd lxc In-Reply-To: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> References: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> Message-ID: <1350822019-15079-5-git-send-email-dominick.grift@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- policy/modules/kernel/terminal.if | 19 +++++++++++++++++++ 1 files changed, 19 insertions(+), 0 deletions(-) diff --git a/policy/modules/kernel/terminal.if b/policy/modules/kernel/terminal.if index 01dd2f1..771bce1 100644 --- a/policy/modules/kernel/terminal.if +++ b/policy/modules/kernel/terminal.if @@ -384,6 +384,25 @@ interface(`term_getattr_pty_fs',` ######################################## ## +## Relabel from and to pty filesystem. +## +## +## +## Domain allowed access. +## +## +# +interface(`term_relabel_pty_fs',` + gen_require(` + type devpts_t; + ') + + dev_list_all_dev_nodes($1) + allow $1 devpts_t:filesystem { relabelto relabelfrom }; +') + +######################################## +## ## Do not audit attempts to get the ## attributes of the /dev/pts directory. ## -- 1.7.7.6