From 135b1b4c541bbed1406af58dc66d27a6e12a1378 Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Wed, 9 Jun 2010 08:22:31 -0400 Subject: [PATCH] Terminal patch from Dan Walsh. --- policy/modules/kernel/terminal.if | 19 +++++++++++++++++++ policy/modules/kernel/terminal.te | 2 +- 2 files changed, 20 insertions(+), 1 deletion(-) diff --git a/policy/modules/kernel/terminal.if b/policy/modules/kernel/terminal.if index 56ddd9931..a905c0afe 100644 --- a/policy/modules/kernel/terminal.if +++ b/policy/modules/kernel/terminal.if @@ -651,6 +651,25 @@ interface(`term_use_controlling_term',` allow $1 devtty_t:chr_file { rw_term_perms lock append }; ') +######################################## +## +## Do not audit attempts to get attributes +## on the pty multiplexor (/dev/ptmx). +## +## +## +## Domain to not audit. +## +## +# +interface(`term_dontaudit_getattr_ptmx',` + gen_require(` + type ptmx_t; + ') + + dontaudit $1 ptmx_t:chr_file getattr; +') + ######################################## ## ## Read and write the pty multiplexor (/dev/ptmx). diff --git a/policy/modules/kernel/terminal.te b/policy/modules/kernel/terminal.te index 9b7930913..1d70a0445 100644 --- a/policy/modules/kernel/terminal.te +++ b/policy/modules/kernel/terminal.te @@ -1,5 +1,5 @@ -policy_module(terminal, 1.8.0) +policy_module(terminal, 1.8.1) ######################################## #