1 |
commit: 74986b6148745779596c8604e6f6e489a2c89c13 |
2 |
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
3 |
AuthorDate: Sun Nov 23 12:46:08 2014 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Nov 23 12:46:08 2014 +0000 |
6 |
URL: http://sources.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=74986b61 |
7 |
|
8 |
OpenRC cgroup helper requires dac_override privilege |
9 |
|
10 |
Managing and updating cgroups through the kernel-invoked openrc cgroup |
11 |
helper has the helper run under root privileges, but accessing files |
12 |
(reading mostly) that are owned by a different user. |
13 |
|
14 |
--- |
15 |
policy/modules/contrib/openrc.te | 1 + |
16 |
1 file changed, 1 insertion(+) |
17 |
|
18 |
diff --git a/policy/modules/contrib/openrc.te b/policy/modules/contrib/openrc.te |
19 |
index bf5a336..91afb6e 100644 |
20 |
--- a/policy/modules/contrib/openrc.te |
21 |
+++ b/policy/modules/contrib/openrc.te |
22 |
@@ -13,6 +13,7 @@ role system_r types openrc_cgroup_release_t; |
23 |
# OpenRC cgroup release policy |
24 |
# |
25 |
|
26 |
+allow openrc_cgroup_release_t self:capability dac_override; |
27 |
allow openrc_cgroup_release_t self:unix_stream_socket create_socket_perms; |
28 |
|
29 |
kernel_domtrans_to(openrc_cgroup_release_t, openrc_cgroup_release_exec_t) |