summaryrefslogtreecommitdiff
path: root/sepolicy/kernel.te
diff options
context:
space:
mode:
Diffstat (limited to 'sepolicy/kernel.te')
-rw-r--r--sepolicy/kernel.te4
1 files changed, 4 insertions, 0 deletions
diff --git a/sepolicy/kernel.te b/sepolicy/kernel.te
new file mode 100644
index 0000000..3e391fd
--- /dev/null
+++ b/sepolicy/kernel.te
@@ -0,0 +1,4 @@
+#============= kernel ==============
+allow kernel device:blk_file { create setattr };
+allow kernel device:dir { write add_name };
+allow kernel self:capability mknod;