diff options
Diffstat (limited to 'src/fs/noseclabelfs/dosnoseclabelfs.cil')
-rw-r--r-- | src/fs/noseclabelfs/dosnoseclabelfs.cil | 21 |
1 files changed, 21 insertions, 0 deletions
diff --git a/src/fs/noseclabelfs/dosnoseclabelfs.cil b/src/fs/noseclabelfs/dosnoseclabelfs.cil new file mode 100644 index 0000000..77eecc8 --- /dev/null +++ b/src/fs/noseclabelfs/dosnoseclabelfs.cil @@ -0,0 +1,21 @@ +;; SPDX-FileCopyrightText: © 2023 Dominick Grift <dominick.grift@defensec.nl> +;; SPDX-License-Identifier: Unlicense + +(block dos + + (genfscon "fat" "/" fs_context) + (genfscon "hfs" "/" fs_context) + (genfscon "hfsplus" "/" fs_context) + (genfscon "msdos" "/" fs_context) + (genfscon "ntfs" "/" fs_context) + (genfscon "ntfs-3g" "/" fs_context) + (genfscon "ntfs3" "/" fs_context) + (genfscon "vfat" "/" fs_context) + (genfscon "exfat" "/" fs_context) + + (macro map_fs_files ((type ARG1)) + (allow ARG1 fs (file (map)))) + + (blockinherit .noseclabelfs.template) + + (call .rbacsep.exempt.obj.type (fs))) |