From e04ad5fe9261661572c6091aff14a83b0cc92a10 Mon Sep 17 00:00:00 2001 From: Dominick Grift Date: Sun, 21 Oct 2012 14:20:14 +0200 Subject: [PATCH] For virtd lxc Signed-off-by: Dominick Grift --- policy/modules/kernel/terminal.if | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/policy/modules/kernel/terminal.if b/policy/modules/kernel/terminal.if index 01dd2f1f4..771bce186 100644 --- a/policy/modules/kernel/terminal.if +++ b/policy/modules/kernel/terminal.if @@ -382,6 +382,25 @@ interface(`term_getattr_pty_fs',` allow $1 devpts_t:filesystem getattr; ') +######################################## +## +## Relabel from and to pty filesystem. +## +## +## +## Domain allowed access. +## +## +# +interface(`term_relabel_pty_fs',` + gen_require(` + type devpts_t; + ') + + dev_list_all_dev_nodes($1) + allow $1 devpts_t:filesystem { relabelto relabelfrom }; +') + ######################################## ## ## Do not audit attempts to get the