diff options
author | Chris PeBenito <Christopher.PeBenito@microsoft.com> | 2022-05-23 14:42:58 +0000 |
---|---|---|
committer | Jason Zaman <perfinion@gentoo.org> | 2022-09-03 11:41:55 -0700 |
commit | 1a0b1580c497808ff39f4bb9b6e63cbe916257d6 (patch) | |
tree | d98aea3589d8a9206421efb1d2bbc1103b4f274b | |
parent | iptables: Ioctl cgroup dirs. (diff) | |
download | hardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.tar.gz hardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.tar.bz2 hardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.zip |
devices: Add type for infiniband devices.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com>
Signed-off-by: Jason Zaman <perfinion@gentoo.org>
-rw-r--r-- | policy/modules/kernel/devices.fc | 2 | ||||
-rw-r--r-- | policy/modules/kernel/devices.te | 6 |
2 files changed, 8 insertions, 0 deletions
diff --git a/policy/modules/kernel/devices.fc b/policy/modules/kernel/devices.fc index 7fa4a971..19b06ab7 100644 --- a/policy/modules/kernel/devices.fc +++ b/policy/modules/kernel/devices.fc @@ -165,6 +165,8 @@ ifdef(`distro_suse', ` /dev/dvb/.* -c gen_context(system_u:object_r:v4l_device_t,s0) +/dev/infiniband/.* -c gen_context(system_u:object_r:infiniband_device_t,s0) + /dev/input/.* -c gen_context(system_u:object_r:event_device_t,s0) /dev/input/m.* -c gen_context(system_u:object_r:mouse_device_t,s0) /dev/input/.*mouse.* -c gen_context(system_u:object_r:mouse_device_t,s0) diff --git a/policy/modules/kernel/devices.te b/policy/modules/kernel/devices.te index 06841950..8ac7c212 100644 --- a/policy/modules/kernel/devices.te +++ b/policy/modules/kernel/devices.te @@ -123,6 +123,12 @@ type gpiochip_device_t; dev_node(gpiochip_device_t) # +# Type for /dev/infiniband/* +# +type infiniband_device_t; +dev_node(infiniband_device_t) + +# # Type for /dev/ipmi/0 # type ipmi_device_t; |