3 type fixed_disk_device_t;
7 class blk_file { ioctl getattr setattr read write };
10 # Give qemu_t access to any block device
11 allow qemu_t fixed_disk_device_t:blk_file { ioctl getattr setattr read write };
12 # allow any file to be bindmounted (for /config)
13 allow mount_t file_type:file mounton;