Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/contrib/
Date: Thu, 25 May 2017 17:08:48
Message-Id: 1495731817.8327ce0c3856f07497d5df5d9b77fa820e915cfb.perfinion@gentoo
1 commit: 8327ce0c3856f07497d5df5d9b77fa820e915cfb
2 Author: Jason Zaman <jason <AT> perfinion <DOT> com>
3 AuthorDate: Thu May 25 17:03:37 2017 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Thu May 25 17:03:37 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=8327ce0c
7
8 consolekit: remove gentoo blocks now that its upstreamed
9
10 policy/modules/contrib/consolekit.fc | 5 -----
11 policy/modules/contrib/consolekit.te | 31 +++++++++++--------------------
12 2 files changed, 11 insertions(+), 25 deletions(-)
13
14 diff --git a/policy/modules/contrib/consolekit.fc b/policy/modules/contrib/consolekit.fc
15 index 8b440c56..d4623586 100644
16 --- a/policy/modules/contrib/consolekit.fc
17 +++ b/policy/modules/contrib/consolekit.fc
18 @@ -9,8 +9,3 @@
19 /run/ConsoleKit(/.*)? gen_context(system_u:object_r:consolekit_var_run_t,s0)
20 /run/consolekit\.pid -- gen_context(system_u:object_r:consolekit_var_run_t,s0)
21 /run/console-kit-daemon\.pid -- gen_context(system_u:object_r:consolekit_var_run_t,s0)
22 -
23 -ifdef(`distro_gentoo',`
24 -# Bug 497986
25 -/usr/lib/ConsoleKit/.* -- gen_context(system_u:object_r:bin_t,s0)
26 -')
27
28 diff --git a/policy/modules/contrib/consolekit.te b/policy/modules/contrib/consolekit.te
29 index 19d4d1b4..d51634ea 100644
30 --- a/policy/modules/contrib/consolekit.te
31 +++ b/policy/modules/contrib/consolekit.te
32 @@ -54,7 +54,8 @@ corecmd_exec_bin(consolekit_t)
33 corecmd_exec_shell(consolekit_t)
34
35 dev_read_urand(consolekit_t)
36 -dev_read_sysfs(consolekit_t)
37 +dev_rw_sysfs(consolekit_t)
38 +dev_setattr_all_chr_files(consolekit_t)
39
40 domain_read_all_domains_state(consolekit_t)
41 domain_use_interactive_fds(consolekit_t)
42 @@ -105,6 +106,10 @@ tunable_policy(`use_samba_home_dirs',`
43 ')
44
45 optional_policy(`
46 + cgmanager_stream_connect(consolekit_t)
47 +')
48 +
49 +optional_policy(`
50 dbus_read_lib_files(consolekit_t)
51 dbus_system_domain(consolekit_t, consolekit_exec_t)
52
53 @@ -126,6 +131,10 @@ optional_policy(`
54 ')
55
56 optional_policy(`
57 + devicekit_manage_log_files(consolekit_t)
58 +')
59 +
60 +optional_policy(`
61 hal_ptrace(consolekit_t)
62 ')
63
64 @@ -157,28 +166,10 @@ optional_policy(`
65 optional_policy(`
66 udev_domtrans(consolekit_t)
67 udev_read_db(consolekit_t)
68 + udev_read_pid_files(consolekit_t)
69 udev_signal(consolekit_t)
70 ')
71
72 optional_policy(`
73 unconfined_stream_connect(consolekit_t)
74 ')
75 -
76 -ifdef(`distro_gentoo',`
77 - # consolekit needs to be able to chown /dev nodes when logging in
78 - dev_setattr_all_chr_files(consolekit_t)
79 -
80 - optional_policy(`
81 - udev_read_pid_files(consolekit_t)
82 - ')
83 -
84 - # needs to write to sys for suspend
85 - dev_rw_sysfs(consolekit_t)
86 - optional_policy(`
87 - devicekit_manage_log_files(consolekit_t)
88 - ')
89 -
90 - optional_policy(`
91 - cgmanager_stream_connect(consolekit_t)
92 - ')
93 -')