1 |
commit: b271394b4c9d85aa2bc49c5c3542365f7af575ec |
2 |
Author: Daniel Jurgens <danielj <AT> mellanox <DOT> com> |
3 |
AuthorDate: Mon Nov 27 14:23:08 2017 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Tue Dec 12 07:07:30 2017 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=b271394b |
7 |
|
8 |
networkmanager: Grant access to unlabeled PKeys |
9 |
|
10 |
For controlling IPoIB VLANs |
11 |
|
12 |
Reported-by: Honggang LI <honli <AT> redhat.com> |
13 |
Signed-off-by: Daniel Jurgens <danielj <AT> mellanox.com> |
14 |
Tested-by: Honggang LI <honli <AT> redhat.com> |
15 |
|
16 |
policy/modules/contrib/networkmanager.te | 2 ++ |
17 |
1 file changed, 2 insertions(+) |
18 |
|
19 |
diff --git a/policy/modules/contrib/networkmanager.te b/policy/modules/contrib/networkmanager.te |
20 |
index e8a60aec..b94e7ef3 100644 |
21 |
--- a/policy/modules/contrib/networkmanager.te |
22 |
+++ b/policy/modules/contrib/networkmanager.te |
23 |
@@ -189,6 +189,8 @@ userdom_write_user_tmp_sockets(NetworkManager_t) |
24 |
userdom_dontaudit_use_unpriv_user_fds(NetworkManager_t) |
25 |
userdom_dontaudit_use_user_ttys(NetworkManager_t) |
26 |
|
27 |
+corenet_ib_access_unlabeled_pkeys(NetworkManager_t) |
28 |
+ |
29 |
optional_policy(` |
30 |
avahi_domtrans(NetworkManager_t) |
31 |
avahi_kill(NetworkManager_t) |