diff --git a/policy/modules/kernel/kernel.if b/policy/modules/kernel/kernel.if index 7cbf5d649..649e458b0 100644 --- a/policy/modules/kernel/kernel.if +++ b/policy/modules/kernel/kernel.if @@ -252,6 +252,25 @@ interface(`kernel_rw_pipes',` allow $1 kernel_t:fifo_file { read write }; ') +######################################## +## +## Connect to kernel using a unix +## domain stream socket. +## +## +## +## Domain allowed access. +## +## +# +interface(`kernel_stream_connect',` + gen_require(` + type kernel_t; + ') + + allow $1 kernel_t:unix_stream_socket connectto; +') + ######################################## ## ## Read and write kernel unix datagram sockets. @@ -563,25 +582,6 @@ interface(`kernel_dontaudit_request_load_module',` dontaudit $1 kernel_t:system module_request; ') -######################################## -## -## Connect to kernel using a unix -## domain stream socket. -## -## -## -## Domain allowed access. -## -## -# -interface(`kernel_stream_connect',` - gen_require(` - type kernel_t; - ') - - allow $1 kernel_t:unix_stream_socket connectto; -') - ######################################## ## ## Get information on all System V IPC objects.