Trusted Solaris Administration Overview

Device Clean Scripts

Device clean scripts are special scripts that are run when a device is first allocated. Clean scripts address two security concerns:

The name of a device clean script for a specific device is stored with that device's entry in the device_allocate(4) file. The operations of each device clean program are specific to each device. The following is a list of tasks that a device clean program performs:

Not all allocatable devices require a device clean program. Devices that do not keep states and do not use removable media do not need a device clean program.

Device clean programs for tape, floppy disk, CD-ROM, and audio devices are provided by the Trusted Solaris environment. The configurable nature of the user device allocation mechanism enables an administrator to install new devices and configure device clean programs accordingly.

For more information on device allocation, see Chapter 15, "Managing Devices," in Trusted Solaris Administrator's Procedures.