Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/services/
Date: Mon, 01 Feb 2021 02:10:35
Message-Id: 1612142502.bf4b1f16a4f6a0b415d77ea028996cdadefde3e2.perfinion@gentoo
1 commit: bf4b1f16a4f6a0b415d77ea028996cdadefde3e2
2 Author: Chris PeBenito <pebenito <AT> ieee <DOT> org>
3 AuthorDate: Thu Jan 28 19:57:08 2021 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Mon Feb 1 01:21:42 2021 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=bf4b1f16
7
8 aptcacher: Drop broken config interfaces.
9
10 The aptcacher_etc_t type does not exist in the policy. The block in cron
11 will never be enabled because of this, so drop that too.
12
13 Signed-off-by: Chris PeBenito <pebenito <AT> ieee.org>
14 Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
15
16 policy/modules/services/aptcacher.if | 40 ------------------------------------
17 policy/modules/services/cron.te | 5 -----
18 2 files changed, 45 deletions(-)
19
20 diff --git a/policy/modules/services/aptcacher.if b/policy/modules/services/aptcacher.if
21 index 8c99a699..12c1335a 100644
22 --- a/policy/modules/services/aptcacher.if
23 +++ b/policy/modules/services/aptcacher.if
24 @@ -63,43 +63,3 @@ interface(`aptcacher_stream_connect',`
25 files_search_runtime($1)
26 stream_connect_pattern($1, aptcacher_runtime_t, aptcacher_runtime_t, aptcacher_t)
27 ')
28 -
29 -######################################
30 -## <summary>
31 -## read aptcacher config
32 -## </summary>
33 -## <param name="domain">
34 -## <summary>
35 -## Domain allowed to read it.
36 -## </summary>
37 -## </param>
38 -#
39 -interface(`aptcacher_read_config',`
40 - gen_require(`
41 - type aptcacher_etc_t;
42 - ')
43 -
44 - files_search_etc($1)
45 - allow $1 aptcacher_etc_t:dir list_dir_perms;
46 - allow $1 aptcacher_etc_t:file read_file_perms;
47 -')
48 -
49 -######################################
50 -## <summary>
51 -## mmap and read aptcacher config
52 -## </summary>
53 -## <param name="domain">
54 -## <summary>
55 -## Domain allowed to read it.
56 -## </summary>
57 -## </param>
58 -#
59 -interface(`aptcacher_mmap_read_config',`
60 - gen_require(`
61 - type aptcacher_etc_t;
62 - ')
63 -
64 - files_search_etc($1)
65 - allow $1 aptcacher_etc_t:dir list_dir_perms;
66 - allow $1 aptcacher_etc_t:file mmap_read_file_perms;
67 -')
68
69 diff --git a/policy/modules/services/cron.te b/policy/modules/services/cron.te
70 index 23e990ad..712a84dd 100644
71 --- a/policy/modules/services/cron.te
72 +++ b/policy/modules/services/cron.te
73 @@ -344,11 +344,6 @@ ifdef(`distro_debian',`
74 dpkg_manage_db(system_cronjob_t)
75 ')
76
77 - optional_policy(`
78 - aptcacher_mmap_read_config(system_cronjob_t)
79 - corenet_tcp_connect_aptcacher_port(system_cronjob_t)
80 - ')
81 -
82 optional_policy(`
83 logwatch_search_cache_dir(crond_t)
84 ')