From 795b733a7197f8e02001001c07fba0d9e83dd45f Mon Sep 17 00:00:00 2001 From: Jeremy Solt Date: Fri, 9 Apr 2010 10:14:05 -0400 Subject: [PATCH] pcscd patch from Dan Walsh: manage pub files and fifo files --- policy/modules/services/pcscd.if | 38 ++++++++++++++++++++++++++++++++ 1 file changed, 38 insertions(+) diff --git a/policy/modules/services/pcscd.if b/policy/modules/services/pcscd.if index 913e857e..1c2a0913 100644 --- a/policy/modules/services/pcscd.if +++ b/policy/modules/services/pcscd.if @@ -37,6 +37,44 @@ interface(`pcscd_read_pub_files',` allow $1 pcscd_var_run_t:file read_file_perms; ') +######################################## +## +## Manage pcscd pub files. +## +## +## +## Domain allowed access. +## +## +# +interface(`pcscd_manage_pub_files',` + gen_require(` + type pcscd_var_run_t; + ') + + files_search_pids($1) + manage_files_pattern($1, pcscd_var_run_t, pcscd_var_run_t) +') + +######################################## +## +## Manage pcscd pub fifo files. +## +## +## +## Domain allowed access. +## +## +# +interface(`pcscd_manage_pub_pipes',` + gen_require(` + type pcscd_var_run_t; + ') + + files_search_pids($1) + manage_fifo_files_pattern($1, pcscd_var_run_t, pcscd_var_run_t) +') + ######################################## ## ## Connect to pcscd over an unix stream socket.