aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <Christopher.PeBenito@microsoft.com>2022-05-23 14:42:58 +0000
committerJason Zaman <perfinion@gentoo.org>2022-09-03 11:41:55 -0700
commit1a0b1580c497808ff39f4bb9b6e63cbe916257d6 (patch)
treed98aea3589d8a9206421efb1d2bbc1103b4f274b
parentiptables: Ioctl cgroup dirs. (diff)
downloadhardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.tar.gz
hardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.tar.bz2
hardened-refpolicy-1a0b1580c497808ff39f4bb9b6e63cbe916257d6.zip
devices: Add type for infiniband devices.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com> Signed-off-by: Jason Zaman <perfinion@gentoo.org>
-rw-r--r--policy/modules/kernel/devices.fc2
-rw-r--r--policy/modules/kernel/devices.te6
2 files changed, 8 insertions, 0 deletions
diff --git a/policy/modules/kernel/devices.fc b/policy/modules/kernel/devices.fc
index 7fa4a971..19b06ab7 100644
--- a/policy/modules/kernel/devices.fc
+++ b/policy/modules/kernel/devices.fc
@@ -165,6 +165,8 @@ ifdef(`distro_suse', `
/dev/dvb/.* -c gen_context(system_u:object_r:v4l_device_t,s0)
+/dev/infiniband/.* -c gen_context(system_u:object_r:infiniband_device_t,s0)
+
/dev/input/.* -c gen_context(system_u:object_r:event_device_t,s0)
/dev/input/m.* -c gen_context(system_u:object_r:mouse_device_t,s0)
/dev/input/.*mouse.* -c gen_context(system_u:object_r:mouse_device_t,s0)
diff --git a/policy/modules/kernel/devices.te b/policy/modules/kernel/devices.te
index 06841950..8ac7c212 100644
--- a/policy/modules/kernel/devices.te
+++ b/policy/modules/kernel/devices.te
@@ -123,6 +123,12 @@ type gpiochip_device_t;
dev_node(gpiochip_device_t)
#
+# Type for /dev/infiniband/*
+#
+type infiniband_device_t;
+dev_node(infiniband_device_t)
+
+#
# Type for /dev/ipmi/0
#
type ipmi_device_t;