selinux-policy/backport-Add-the-kernel_read_proc_files-interface.patch
2023-08-24 11:33:18 +08:00

39 lines
1.0 KiB
Diff

From 0d41bd657e613657b01f75645b6168cf5987e387 Mon Sep 17 00:00:00 2001
From: Zdenek Pytela <zpytela@redhat.com>
Date: Thu, 23 Jun 2022 20:49:49 +0200
Subject: [PATCH] Add the kernel_read_proc_files() interface
---
policy/modules/kernel/kernel.if | 18 ++++++++++++++++++
1 file changed, 18 insertions(+)
diff --git a/policy/modules/kernel/kernel.if b/policy/modules/kernel/kernel.if
index 75623cf38f..8a83ed511d 100644
--- a/policy/modules/kernel/kernel.if
+++ b/policy/modules/kernel/kernel.if
@@ -1112,6 +1112,24 @@ interface(`kernel_getattr_proc_files',`
getattr_files_pattern($1, proc_t, proc_t)
')
+########################################
+## <summary>
+## Read generic files in /proc.
+## </summary>
+## <param name="domain">
+## <summary>
+## Domain allowed access.
+## </summary>
+## </param>
+#
+interface(`kernel_read_proc_files',`
+ gen_require(`
+ type proc_t;
+ ')
+
+ read_files_pattern($1, proc_t, proc_t)
+')
+
########################################
## <summary>
## Read generic symbolic links in /proc.