Add interface to get status of iptables service

Signed-off-by: Dave Sugar <dsugar@tresys.com>
This commit is contained in:
Sugar, David 2019-01-07 19:50:23 +00:00 committed by Chris PeBenito
parent e8ba31557d
commit 43a77c30fa

View File

@ -183,6 +183,25 @@ interface(`iptables_dontaudit_read_pids',`
dontaudit $1 iptables_runtime_t:file read;
')
########################################
## <summary>
## Allow specified domain to get status of iptables service
## </summary>
## <param name="domain">
## <summary>
## Domain allowed access.
## </summary>
## </param>
#
interface(`iptables_status',`
gen_require(`
type iptables_unit_t;
class service status;
')
allow $1 iptables_unit_t:service status;
')
########################################
## <summary>
## All of the rules required to