From 7381deb2920126ef24e1af85c8045f38bc428ed1 Mon Sep 17 00:00:00 2001 From: Luis Ressel Date: Sat, 1 Feb 2014 12:36:49 +0100 Subject: [PATCH] kernel/files.if: Add files_dontaudit_list_var interface This is required for an update of the couchdb policy. --- policy/modules/kernel/files.if | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/policy/modules/kernel/files.if b/policy/modules/kernel/files.if index 566314fe4..692db4593 100644 --- a/policy/modules/kernel/files.if +++ b/policy/modules/kernel/files.if @@ -5179,6 +5179,25 @@ interface(`files_list_var',` allow $1 var_t:dir list_dir_perms; ') +######################################## +## +## Do not audit attempts to list +## the contents of /var. +## +## +## +## Domain to not audit. +## +## +# +interface(`files_dontaudit_list_var',` + gen_require(` + type var_t; + ') + + dontaudit $1 var_t:dir list_dir_perms; +') + ######################################## ## ## Create, read, write, and delete directories