From e37087d58b6422d0d90e321d9172cf396186fa46 Mon Sep 17 00:00:00 2001 From: Zdenek Pytela Date: Wed, 24 Aug 2022 15:47:25 +0200 Subject: [PATCH] Add userdom_view_all_users_keys() interface --- policy/modules/system/userdomain.if | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/policy/modules/system/userdomain.if b/policy/modules/system/userdomain.if index 97c27a957a..d23f2ce305 100644 --- a/policy/modules/system/userdomain.if +++ b/policy/modules/system/userdomain.if @@ -4811,6 +4811,24 @@ interface(`userdom_read_all_users_keys',` allow $1 userdomain:key read; ') +######################################## +## +## View keys for all user domains. +## +## +## +## Domain allowed access. +## +## +# +interface(`userdom_view_all_users_keys',` + gen_require(` + attribute userdomain; + ') + + allow $1 userdomain:key view; +') + ######################################## ## ## Write keys for all user domains.