aboutgitcodebugslistschat
path: root/contrib/selinux/passt.if
diff options
context:
space:
mode:
authorStefano Brivio <sbrivio@redhat.com>2022-03-28 11:08:39 +0200
committerStefano Brivio <sbrivio@redhat.com>2022-03-29 15:35:38 +0200
commit1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb (patch)
tree593b882b328424b079568bf8945cbdfe225c21e7 /contrib/selinux/passt.if
parente9d573b14f28bde604718513ed3d499f621090d8 (diff)
downloadpasst-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar.gz
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar.bz2
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar.lz
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar.xz
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.tar.zst
passt-1f4b7fa0d75d25f518047e77c88718ec1cc3f5bb.zip
passt, pasta: Add examples of SELinux policy modules
These should cover any reasonably common use case in distributions. Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Diffstat (limited to 'contrib/selinux/passt.if')
-rw-r--r--contrib/selinux/passt.if17
1 files changed, 17 insertions, 0 deletions
diff --git a/contrib/selinux/passt.if b/contrib/selinux/passt.if
new file mode 100644
index 0000000..3ccb7f4
--- /dev/null
+++ b/contrib/selinux/passt.if
@@ -0,0 +1,17 @@
+# SPDX-License-Identifier: AGPL-3.0-or-later
+#
+# PASST - Plug A Simple Socket Transport
+# for qemu/UNIX domain socket mode
+#
+# contrib/selinux/passt.if - SELinux profile example: Interface File for passt
+#
+# Copyright (c) 2022 Red Hat GmbH
+# Author: Stefano Brivio <sbrivio@redhat.com>
+
+interface('passt_read_data','
+ gen_require(`
+ type passt_data_t;
+ ')
+ allow $1 passt_t:dir { search add_name };
+ allow $1 passt_t:file { open read getattr };
+')