Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/admin/
Date: Mon, 28 May 2012 08:42:02
Message-Id: 1338194491.5974ae4f57cf1ac6919f8b3393a98103051156bb.SwifT@gentoo
1 commit: 5974ae4f57cf1ac6919f8b3393a98103051156bb
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Mon May 28 08:41:31 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Mon May 28 08:41:31 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=5974ae4f
7
8 Do not audit dmesg attempts to read/write /dev/console when not labeled properly yet
9
10 ---
11 policy/modules/admin/dmesg.te | 1 +
12 1 files changed, 1 insertions(+), 0 deletions(-)
13
14 diff --git a/policy/modules/admin/dmesg.te b/policy/modules/admin/dmesg.te
15 index 72bc6d8..12f7627 100644
16 --- a/policy/modules/admin/dmesg.te
17 +++ b/policy/modules/admin/dmesg.te
18 @@ -27,6 +27,7 @@ kernel_list_proc(dmesg_t)
19 kernel_read_proc_symlinks(dmesg_t)
20
21 dev_read_sysfs(dmesg_t)
22 +dev_dontaudit_rw_generic_chr_files(dmesg_t) # early access when /dev/console isn't relabeled by udev yet
23
24 fs_search_auto_mountpoints(dmesg_t)