Add storage patch, from Dan Walsh.

This commit is contained in:
Chris PeBenito 2009-11-19 09:03:36 -05:00
parent deb527262a
commit 53c73dc785
3 changed files with 3 additions and 2 deletions

View File

@ -28,6 +28,7 @@
/dev/megadev.* -c gen_context(system_u:object_r:removable_device_t,s0) /dev/megadev.* -c gen_context(system_u:object_r:removable_device_t,s0)
/dev/mmcblk.* -b gen_context(system_u:object_r:removable_device_t,s0) /dev/mmcblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
/dev/mspblk.* -b gen_context(system_u:object_r:removable_device_t,s0) /dev/mspblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
/dev/mtd.* -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/nb[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh) /dev/nb[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/optcd -b gen_context(system_u:object_r:removable_device_t,s0) /dev/optcd -b gen_context(system_u:object_r:removable_device_t,s0)
/dev/p[fg][0-3] -b gen_context(system_u:object_r:removable_device_t,s0) /dev/p[fg][0-3] -b gen_context(system_u:object_r:removable_device_t,s0)

View File

@ -529,7 +529,7 @@ interface(`storage_dontaudit_read_removable_device',`
') ')
dontaudit $1 removable_device_t:blk_file { getattr ioctl read }; dontaudit $1 removable_device_t:blk_file read_blk_file_perms;
') ')
######################################## ########################################

View File

@ -1,5 +1,5 @@
policy_module(storage, 1.7.0) policy_module(storage, 1.7.1)
######################################## ########################################
# #