diff --git a/policy/modules/system/sysnetwork.if b/policy/modules/system/sysnetwork.if index 363e98d27..58a7d89c8 100644 --- a/policy/modules/system/sysnetwork.if +++ b/policy/modules/system/sysnetwork.if @@ -64,6 +64,25 @@ interface(`sysnet_dontaudit_use_dhcpc_fds',` dontaudit $1 dhcpc_t:fd use; ') +######################################## +## +## Do not audit attempts to read/write to the +## dhcp unix stream socket descriptors. +## +## +## +## Domain to not audit. +## +## +# +interface(`sysnet_dontaudit_rw_dhcpc_unix_stream_sockets',` + gen_require(` + type dhcpc_t; + ') + + dontaudit $1 dhcpc_t:unix_stream_socket { read write }; +') + ######################################## ## ## Send a SIGCHLD signal to the dhcp client.