Skip to content

Commit

Permalink
Update policy for rpc-virtstorage
Browse files Browse the repository at this point in the history
In particular, domain transition on udev and parted execution and
r/w operations on fixed disk devices were allowed.

Resolves: rhbz#2305564
  • Loading branch information
zpytela committed Sep 6, 2024
1 parent d9cd360 commit 1849ca3
Showing 1 changed file with 12 additions and 0 deletions.
12 changes: 12 additions & 0 deletions policy/modules/contrib/virt.te
Original file line number Diff line number Diff line change
Expand Up @@ -2334,23 +2334,35 @@ manage_files_pattern(virtstoraged_t, virt_var_lib_t, virt_var_lib_t)

manage_lnk_files_pattern(virtstoraged_t, virt_etc_rw_t, virt_etc_rw_t)

kernel_get_sysvipc_info(virtstoraged_t)
kernel_io_uring_use(virtstoraged_t)

corecmd_exec_bin(virtstoraged_t)

fs_getattr_all_fs(virtstoraged_t)
fs_getattr_configfs_dirs(virtstoraged_t)

storage_raw_read_fixed_disk(virtstoraged_t)
storage_raw_write_fixed_disk(virtstoraged_t)

userdom_read_user_home_content_files(virtstoraged_t)

optional_policy(`
dnsmasq_filetrans_named_content_fromdir(virtstoraged_t, virtstoraged_var_run_t)
')

optional_policy(`
fstools_domtrans(virtstoraged_t)
')

optional_policy(`
lvm_domtrans(virtstoraged_t)
')

optional_policy(`
udev_domtrans(virtstoraged_t)
')

#######################################
#
# virtvboxd local policy
Expand Down

0 comments on commit 1849ca3

Please sign in to comment.