kernel: introduce kernel_dontaudit_read_kernel_sysctl

Signed-off-by: Jason Zaman <jason@perfinion.com>
This commit is contained in:
Jason Zaman 2019-01-12 16:03:42 +08:00 committed by Chris PeBenito
parent d83a104eda
commit 4ed30f7492

View File

@ -2012,6 +2012,24 @@ interface(`kernel_dontaudit_search_kernel_sysctl',`
dontaudit $1 sysctl_kernel_t:dir search;
')
#######################################
## <summary>
## Do not audit attempted reading of kernel sysctls
## </summary>
## <param name="domain">
## <summary>
## Domain to not audit accesses from
## </summary>
## </param>
#
interface(`kernel_dontaudit_read_kernel_sysctl',`
gen_require(`
type sysctl_kernel_t;
')
dontaudit $1 sysctl_kernel_t:file read_file_perms;
')
########################################
## <summary>
## Read generic crypto sysctls.