Add neccessary permissions for losetup

This allows losetup to bind mount_loopback_t files to loop devices.
This commit is contained in:
Luis Ressel 2014-08-12 00:24:15 +02:00 committed by Chris PeBenito
parent d18b43bae7
commit 9946965a53
2 changed files with 10 additions and 0 deletions

View File

@ -299,6 +299,11 @@ ifdef(`distro_redhat',`
fs_rw_tmpfs_chr_files(kernel_t)
')
optional_policy(`
# loop devices
fstools_use_fds(kernel_t)
')
optional_policy(`
hotplug_search_config(kernel_t)
')

View File

@ -94,6 +94,8 @@ dev_rw_sysfs(fsadm_t)
dev_getattr_usbfs_dirs(fsadm_t)
# Access to /dev/mapper/control
dev_rw_lvm_control(fsadm_t)
# for losetup
dev_rw_loop_control(fsadm_t)
domain_use_interactive_fds(fsadm_t)
@ -125,6 +127,9 @@ files_search_all(fsadm_t)
mls_file_read_all_levels(fsadm_t)
mls_file_write_all_levels(fsadm_t)
# losetup: bind mount_loopback_t files to loop devices
mount_rw_loopback_files(fsadm_t)
storage_raw_read_fixed_disk(fsadm_t)
storage_raw_write_fixed_disk(fsadm_t)
storage_raw_read_removable_device(fsadm_t)