Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/admin/
Date: Sun, 02 Feb 2014 12:18:40
Message-Id: 1391343453.2a38128e3940d14e9cae65ecdb80ab0812af9e9b.swift@gentoo
1 commit: 2a38128e3940d14e9cae65ecdb80ab0812af9e9b
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Sun Feb 2 12:17:33 2014 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Sun Feb 2 12:17:33 2014 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=2a38128e
7
8 Fix bug #499036 - avc_running assertion fails otherwise
9
10 ---
11 policy/modules/admin/usermanage.te | 14 ++++++++++++++
12 1 file changed, 14 insertions(+)
13
14 diff --git a/policy/modules/admin/usermanage.te b/policy/modules/admin/usermanage.te
15 index 3ba4972..7bfba16 100644
16 --- a/policy/modules/admin/usermanage.te
17 +++ b/policy/modules/admin/usermanage.te
18 @@ -565,3 +565,17 @@ optional_policy(`
19 rpm_use_fds(useradd_t)
20 rpm_rw_pipes(useradd_t)
21 ')
22 +
23 +ifdef(`distro_gentoo',`
24 + ########################################
25 + # groupadd_t
26 +
27 + # fix bug #499036
28 + allow groupadd_t self:netlink_selinux_socket { create bind };
29 +
30 + ########################################
31 + # useradd_t
32 +
33 + # fix bug #499036
34 + allow useradd_t self:netlink_selinux_socket { create bind };
35 +')