From 105e623ee883586a70be6215659175b40f35b7b2 Mon Sep 17 00:00:00 2001 From: George Zenner Date: Fri, 10 Feb 2023 15:45:09 -0600 Subject: [PATCH] Signed-off-by: George Zenner modified: policy/modules/system/sysnetwork.if --- policy/modules/system/sysnetwork.if | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/policy/modules/system/sysnetwork.if b/policy/modules/system/sysnetwork.if index e9619743d..64c5d5b49 100644 --- a/policy/modules/system/sysnetwork.if +++ b/policy/modules/system/sysnetwork.if @@ -83,6 +83,25 @@ interface(`sysnet_dontaudit_use_dhcpc_fds',` dontaudit $1 dhcpc_t:fd use; ') +######################################## +## +## Do not audit attempts to read/write to the +## dhcp unix datagram socket descriptors. +## +## +## +## Domain to not audit. +## +## +# +interface(`sysnet_dontaudit_rw_dhcpc_unix_dgram_sockets',` + gen_require(` + type dhcpc_t; + ') + + dontaudit $1 dhcpc_t:unix_dgram_socket { read write }; +') + ######################################## ## ## Do not audit attempts to read/write to the