Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/contrib/
Date: Fri, 28 Nov 2014 10:04:13
Message-Id: 1416746768.74986b6148745779596c8604e6f6e489a2c89c13.swift@gentoo
1 commit: 74986b6148745779596c8604e6f6e489a2c89c13
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Sun Nov 23 12:46:08 2014 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Sun Nov 23 12:46:08 2014 +0000
6 URL: http://sources.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=74986b61
7
8 OpenRC cgroup helper requires dac_override privilege
9
10 Managing and updating cgroups through the kernel-invoked openrc cgroup
11 helper has the helper run under root privileges, but accessing files
12 (reading mostly) that are owned by a different user.
13
14 ---
15 policy/modules/contrib/openrc.te | 1 +
16 1 file changed, 1 insertion(+)
17
18 diff --git a/policy/modules/contrib/openrc.te b/policy/modules/contrib/openrc.te
19 index bf5a336..91afb6e 100644
20 --- a/policy/modules/contrib/openrc.te
21 +++ b/policy/modules/contrib/openrc.te
22 @@ -13,6 +13,7 @@ role system_r types openrc_cgroup_release_t;
23 # OpenRC cgroup release policy
24 #
25
26 +allow openrc_cgroup_release_t self:capability dac_override;
27 allow openrc_cgroup_release_t self:unix_stream_socket create_socket_perms;
28
29 kernel_domtrans_to(openrc_cgroup_release_t, openrc_cgroup_release_exec_t)