dontaudit mount writes to newly mounted filesystems

Signed-off-by: Chris Richards <gizmo@giz-works.com>
This commit is contained in:
Chris Richards 2010-11-08 19:25:32 -06:00 committed by Chris PeBenito
parent 3e99a17663
commit 7644a58c1f

View File

@ -1463,7 +1463,25 @@ interface(`files_list_root',`
allow $1 root_t:lnk_file { read_lnk_file_perms ioctl lock };
')
########################################
#############################################################
## <summary>
## Do not audit attempts to write to / dirs.
## </summary>
## <param name="domain">
## <summary>
## Domain to not audit.
## </summary>
## </param>
#
interface(`files_dontaudit_write_root_dirs',`
gen_require(`
type root_t;
')
dontaudit $1 root_t:dir write;
')
###################
## <summary>
## Do not audit attempts to write
## files in the root directory.