aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <Christopher.PeBenito@microsoft.com>2022-05-02 15:41:51 +0000
committerJason Zaman <perfinion@gentoo.org>2022-09-03 11:41:55 -0700
commit912c6ce6823ef9f897706febca1af1de78c44c4a (patch)
tree7898fb1ea9c3a527cb7b86afa3339760b2a8b127
parentcontainer, docker: Fixes for containerd and kubernetes testing. (diff)
downloadhardened-refpolicy-912c6ce6823ef9f897706febca1af1de78c44c4a.tar.gz
hardened-refpolicy-912c6ce6823ef9f897706febca1af1de78c44c4a.tar.bz2
hardened-refpolicy-912c6ce6823ef9f897706febca1af1de78c44c4a.zip
devices: Add type for SAS management devices.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com> Signed-off-by: Jason Zaman <perfinion@gentoo.org>
-rw-r--r--policy/modules/kernel/devices.fc1
-rw-r--r--policy/modules/kernel/devices.te6
2 files changed, 7 insertions, 0 deletions
diff --git a/policy/modules/kernel/devices.fc b/policy/modules/kernel/devices.fc
index bd08f81d..bd0977e3 100644
--- a/policy/modules/kernel/devices.fc
+++ b/policy/modules/kernel/devices.fc
@@ -77,6 +77,7 @@
/dev/mixer.* -c gen_context(system_u:object_r:sound_device_t,s0)
/dev/mmetfgrab -c gen_context(system_u:object_r:scanner_device_t,s0)
/dev/modem -c gen_context(system_u:object_r:modem_device_t,s0)
+/dev/mpt[2-9]*ctl -c gen_context(system_u:object_r:mptctl_device_t,s0)
/dev/mpu401.* -c gen_context(system_u:object_r:sound_device_t,s0)
/dev/msr.* -c gen_context(system_u:object_r:cpu_device_t,s0)
/dev/ndctl[0-9] -c gen_context(system_u:object_r:nvram_device_t,s0)
diff --git a/policy/modules/kernel/devices.te b/policy/modules/kernel/devices.te
index 8c949fb0..06841950 100644
--- a/policy/modules/kernel/devices.te
+++ b/policy/modules/kernel/devices.te
@@ -199,6 +199,12 @@ type mouse_device_t;
dev_node(mouse_device_t)
#
+# Serial Attached SCSI Management device
+#
+type mptctl_device_t;
+dev_node(mptctl_device_t)
+
+#
# Type for /dev/cpu/mtrr and /proc/mtrr
#
type mtrr_device_t;