Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Mon, 30 Sep 2013 19:03:42
Message-Id: 1380567613.b92fcf621c4710e0d54decc86af7059689d3e2a4.swift@gentoo
1 commit: b92fcf621c4710e0d54decc86af7059689d3e2a4
2 Author: Chris PeBenito <cpebenito <AT> tresys <DOT> com>
3 AuthorDate: Fri Sep 27 21:09:43 2013 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Mon Sep 30 19:00:13 2013 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=b92fcf62
7
8 Silence symlink reading by setfiles since it doesn't follow symlinks anyway.
9
10 ---
11 policy/modules/system/selinuxutil.te | 3 ++-
12 1 file changed, 2 insertions(+), 1 deletion(-)
13
14 diff --git a/policy/modules/system/selinuxutil.te b/policy/modules/system/selinuxutil.te
15 index 4c01b9b..5e7df70 100644
16 --- a/policy/modules/system/selinuxutil.te
17 +++ b/policy/modules/system/selinuxutil.te
18 @@ -1,4 +1,4 @@
19 -policy_module(selinuxutil, 1.17.1)
20 +policy_module(selinuxutil, 1.17.2)
21
22 gen_require(`
23 bool secure_mode;
24 @@ -560,6 +560,7 @@ files_read_etc_files(setfiles_t)
25 files_list_all(setfiles_t)
26 files_relabel_all_files(setfiles_t)
27 files_read_usr_symlinks(setfiles_t)
28 +files_dontaudit_read_all_symlinks(setfiles_t)
29
30 fs_getattr_xattr_fs(setfiles_t)
31 fs_list_all(setfiles_t)