diff --git a/policy/modules/kernel/filesystem.if b/policy/modules/kernel/filesystem.if index 62911f122..98f3af5d4 100644 --- a/policy/modules/kernel/filesystem.if +++ b/policy/modules/kernel/filesystem.if @@ -1982,6 +1982,24 @@ interface(`fs_manage_dos_files',` manage_files_pattern($1, dosfs_t, dosfs_t) ') +######################################## +## +## List dirs in efivarfs filesystem. +## +## +## +## Domain allowed access. +## +## +# +interface(`fs_list_efivars',` + gen_require(` + type efivarfs_t; + ') + + list_dirs_pattern($1, efivarfs_t, efivarfs_t) +') + ####################################### ## ## Read files in efivarfs