aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Göttsche <cgzones@googlemail.com>2018-01-01 12:32:34 +0100
committerSven Vermeulen <swift@gentoo.org>2018-01-18 17:31:23 +0100
commit3cfa359b54921eda7f449dd445dadd7e231e4eb3 (patch)
treed4b6018ff5cf2e5c35b5e6c744b231332f3dfa50 /policy/modules/kernel/filesystem.if
parenthostname: Module version bump. (diff)
downloadhardened-refpolicy-3cfa359b54921eda7f449dd445dadd7e231e4eb3.tar.gz
hardened-refpolicy-3cfa359b54921eda7f449dd445dadd7e231e4eb3.tar.bz2
hardened-refpolicy-3cfa359b54921eda7f449dd445dadd7e231e4eb3.zip
filesystem: add fs_rw_inherited_hugetlbfs_files for apache module
Diffstat (limited to 'policy/modules/kernel/filesystem.if')
-rw-r--r--policy/modules/kernel/filesystem.if18
1 files changed, 18 insertions, 0 deletions
diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if
index 168f204ad..7f245e29d 100644
--- a/policy/modules/kernel/filesystem.if
+++ b/policy/modules/kernel/filesystem.if
@@ -2306,6 +2306,24 @@ interface(`fs_manage_hugetlbfs_dirs',`
########################################
## <summary>
+## Read and write inherited hugetlbfs files.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`fs_rw_inherited_hugetlbfs_files',`
+ gen_require(`
+ type hugetlbfs_t;
+ ')
+
+ allow $1 hugetlbfs_t:file rw_inherited_file_perms;
+')
+
+########################################
+## <summary>
## Read and write hugetlbfs files.
## </summary>
## <param name="domain">