From: dominick.grift@gmail.com (Dominick Grift) Date: Sun, 21 Oct 2012 14:20:17 +0200 Subject: [refpolicy] [PATCH 07/10] For virtd lxc In-Reply-To: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> References: <1350822019-15079-1-git-send-email-dominick.grift@gmail.com> Message-ID: <1350822019-15079-8-git-send-email-dominick.grift@gmail.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Signed-off-by: Dominick Grift --- policy/modules/kernel/files.if | 18 ++++++++++++++++++ 1 files changed, 18 insertions(+), 0 deletions(-) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index e188a21..96b91e0 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -1874,6 +1874,24 @@ interface(`files_delete_root_dir_entry',` ######################################## ## +## Relabel to and from rootfs file system. +## +## +## +## Domain allowed access. +## +## +# +interface(`files_relabel_rootfs',` + gen_require(` + type root_t; + ') + + allow $1 root_t:filesystem { relabelto relabelfrom }; +') + +######################################## +## ## Unmount a rootfs filesystem. ## ## -- 1.7.7.6