aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChris PeBenito <Christopher.PeBenito@microsoft.com>2022-05-23 14:43:46 +0000
committerJason Zaman <perfinion@gentoo.org>2022-09-03 11:41:55 -0700
commit7416d4fe8d6de7bfbc5df99866ab0b754268414b (patch)
tree024acec1046ee76b58f8cf0879426566c88b2a47
parentdevices: Add type for infiniband devices. (diff)
downloadhardened-refpolicy-7416d4fe8d6de7bfbc5df99866ab0b754268414b.tar.gz
hardened-refpolicy-7416d4fe8d6de7bfbc5df99866ab0b754268414b.tar.bz2
hardened-refpolicy-7416d4fe8d6de7bfbc5df99866ab0b754268414b.zip
storage: Add fc for /dev/ng*n* devices.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com> Signed-off-by: Jason Zaman <perfinion@gentoo.org>
-rw-r--r--policy/modules/kernel/storage.fc1
1 files changed, 1 insertions, 0 deletions
diff --git a/policy/modules/kernel/storage.fc b/policy/modules/kernel/storage.fc
index 46395b8fc..3033ac4de 100644
--- a/policy/modules/kernel/storage.fc
+++ b/policy/modules/kernel/storage.fc
@@ -35,6 +35,7 @@
/dev/mtd.* -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/mtd.* -c gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/nb[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
+/dev/ng[0-9]+n[0-9]+ -c gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/nvme[0-9]+ -c gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/nvme[0-9]n[^/]+ -b gen_context(system_u:object_r:fixed_disk_device_t,mls_systemhigh)
/dev/optcd -b gen_context(system_u:object_r:removable_device_t,s0)