diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if index 618e39612..7f9cf0f7e 100644 --- a/policy/modules/kernel/filesystem.if +++ b/policy/modules/kernel/filesystem.if @@ -1846,6 +1846,26 @@ interface(`fs_manage_dos_files',` manage_files_pattern($1, dosfs_t, dosfs_t) ') +####################################### +## +## Read files in efivarfs +## - contains Linux Kernel configuration options for UEFI systems +## +## +## +## Domain allowed access. +## +## +## +# +interface(`fs_read_efivarfs_files',` + gen_require(` + type efivarfs_t; + ') + + read_files_pattern($1, efivarfs_t, efivarfs_t) +') + ######################################## ## ## Read eventpollfs files.