Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/contrib/
Date: Sun, 01 Jan 2017 16:38:28
Message-Id: 1483288637.b408a4f834ead0cf75539fcdd31f947c7841ec9a.perfinion@gentoo
1 commit: b408a4f834ead0cf75539fcdd31f947c7841ec9a
2 Author: Jason Zaman <jason <AT> perfinion <DOT> com>
3 AuthorDate: Fri May 27 20:44:51 2016 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Jan 1 16:37:17 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=b408a4f8
7
8 virt: virtlockd doesnt need ps_process_pattern
9
10 policy/modules/contrib/virt.te | 6 ++++--
11 1 file changed, 4 insertions(+), 2 deletions(-)
12
13 diff --git a/policy/modules/contrib/virt.te b/policy/modules/contrib/virt.te
14 index 0924307..53233cb 100644
15 --- a/policy/modules/contrib/virt.te
16 +++ b/policy/modules/contrib/virt.te
17 @@ -1308,6 +1308,10 @@ kernel_dontaudit_read_system_state(virt_leaseshelper_t)
18 allow virtlockd_t self:capability dac_override;
19 allow virtlockd_t self:fifo_file rw_fifo_file_perms;
20
21 +allow virtlockd_t virtd_t:dir list_dir_perms;
22 +allow virtlockd_t virtd_t:file read_file_perms;
23 +allow virtlockd_t virtd_t:lnk_file read_lnk_file_perms;
24 +
25 allow virtlockd_t virt_image_type:dir list_dir_perms;
26 allow virtlockd_t virt_image_type:file rw_file_perms;
27
28 @@ -1326,8 +1330,6 @@ files_pid_filetrans(virtlockd_t, virtlockd_run_t, file)
29
30 can_exec(virtlockd_t, virtlockd_exec_t)
31
32 -ps_process_pattern(virtlockd_t, virtd_t)
33 -
34 files_read_etc_files(virtlockd_t)
35 files_list_var_lib(virtlockd_t)