diff --git a/policy/modules/kernel/devices.if b/policy/modules/kernel/devices.if index 7f97cb26c..89beb51bb 100644 --- a/policy/modules/kernel/devices.if +++ b/policy/modules/kernel/devices.if @@ -108,6 +108,24 @@ interface(`dev_getattr_fs',` allow $1 device_t:filesystem getattr; ') +######################################## +## +## Watch the directories in /dev. +## +## +## +## Domain allowed access. +## +## +# +interface(`dev_watch_dev_dirs',` + gen_require(` + type device_t; + ') + + allow $1 device_t:dir watch; +') + ######################################## ## ## Mount a filesystem on /dev