1 |
commit: e81132e1d71edbe52e2199912b8b75353b982fe0 |
2 |
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
3 |
AuthorDate: Sat Dec 29 17:13:39 2012 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Sat Dec 29 17:13:39 2012 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=e81132e1 |
7 |
|
8 |
Udev init script writes to /proc/sys/kernel/hotplug |
9 |
|
10 |
The pseudofile, labeled proc_t, should be writeable by the init scripts. The |
11 |
udev init script for instance runs |
12 |
echo "" > /proc/sys/kernel/hotplug |
13 |
|
14 |
--- |
15 |
policy/modules/system/init.te | 2 ++ |
16 |
1 files changed, 2 insertions(+), 0 deletions(-) |
17 |
|
18 |
diff --git a/policy/modules/system/init.te b/policy/modules/system/init.te |
19 |
index e55e9f1..c44b9d0 100644 |
20 |
--- a/policy/modules/system/init.te |
21 |
+++ b/policy/modules/system/init.te |
22 |
@@ -907,6 +907,8 @@ ifdef(`distro_gentoo',` |
23 |
manage_dirs_pattern(initrc_t, initrc_var_run_t, initrc_var_run_t) |
24 |
files_pid_filetrans(initrc_t, initrc_var_run_t, dir) |
25 |
|
26 |
+ kernel_write_proc_files(initrc_t) |
27 |
+ |
28 |
dev_manage_sysfs_dirs(initrc_t) |
29 |
|
30 |
files_create_pid_dirs(initrc_t) |