Add storage patch, from Dan Walsh.
This commit is contained in:
parent
deb527262a
commit
53c73dc785
@ -28,6 +28,7 @@
|
|||||||
/dev/megadev.* -c gen_context(system_u:object_r:removable_device_t,s0)
|
/dev/megadev.* -c gen_context(system_u:object_r:removable_device_t,s0)
|
||||||
/dev/mmcblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
|
/dev/mmcblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
|
||||||
/dev/mspblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
|
/dev/mspblk.* -b gen_context(system_u:object_r:removable_device_t,s0)
|
||||||
|
/dev/mtd.* -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
|
||||||
/dev/nb[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
|
/dev/nb[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
|
||||||
/dev/optcd -b gen_context(system_u:object_r:removable_device_t,s0)
|
/dev/optcd -b gen_context(system_u:object_r:removable_device_t,s0)
|
||||||
/dev/p[fg][0-3] -b gen_context(system_u:object_r:removable_device_t,s0)
|
/dev/p[fg][0-3] -b gen_context(system_u:object_r:removable_device_t,s0)
|
||||||
|
@ -529,7 +529,7 @@ interface(`storage_dontaudit_read_removable_device',`
|
|||||||
|
|
||||||
')
|
')
|
||||||
|
|
||||||
dontaudit $1 removable_device_t:blk_file { getattr ioctl read };
|
dontaudit $1 removable_device_t:blk_file read_blk_file_perms;
|
||||||
')
|
')
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
|
@ -1,5 +1,5 @@
|
|||||||
|
|
||||||
policy_module(storage, 1.7.0)
|
policy_module(storage, 1.7.1)
|
||||||
|
|
||||||
########################################
|
########################################
|
||||||
#
|
#
|
||||||
|
Loading…
Reference in New Issue
Block a user