Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/services/, policy/modules/system/
Date: Sun, 10 Feb 2019 04:14:58
Message-Id: 1549771885.1404015272ed6954f662683dfc503bbaac7da319.perfinion@gentoo
1 commit: 1404015272ed6954f662683dfc503bbaac7da319
2 Author: Russell Coker <russell <AT> coker <DOT> com <DOT> au>
3 AuthorDate: Mon Jan 28 08:48:40 2019 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Feb 10 04:11:25 2019 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=14040152
7
8 yet another little patch
9
10 This should all be obvious.
11
12 Signed-off-by: Jason Zaman <jason <AT> perfinion.com>
13
14 policy/modules/services/devicekit.te | 2 ++
15 policy/modules/system/lvm.te | 1 +
16 policy/modules/system/sysnetwork.te | 1 +
17 3 files changed, 4 insertions(+)
18
19 diff --git a/policy/modules/services/devicekit.te b/policy/modules/services/devicekit.te
20 index ca9de7cc..941880ef 100644
21 --- a/policy/modules/services/devicekit.te
22 +++ b/policy/modules/services/devicekit.te
23 @@ -91,6 +91,7 @@ files_pid_filetrans(devicekit_disk_t, devicekit_var_run_t, { dir file })
24 kernel_getattr_message_if(devicekit_disk_t)
25 kernel_list_unlabeled(devicekit_disk_t)
26 kernel_dontaudit_getattr_unlabeled_files(devicekit_disk_t)
27 +kernel_read_crypto_sysctls(devicekit_disk_t)
28 kernel_read_fs_sysctls(devicekit_disk_t)
29 kernel_read_network_state(devicekit_disk_t)
30 kernel_read_software_raid_state(devicekit_disk_t)
31 @@ -108,6 +109,7 @@ dev_getattr_all_chr_files(devicekit_disk_t)
32 dev_getattr_mtrr_dev(devicekit_disk_t)
33 dev_getattr_usbfs_dirs(devicekit_disk_t)
34 dev_manage_generic_files(devicekit_disk_t)
35 +dev_read_rand(devicekit_disk_t)
36 dev_read_urand(devicekit_disk_t)
37 dev_rw_sysfs(devicekit_disk_t)
38
39
40 diff --git a/policy/modules/system/lvm.te b/policy/modules/system/lvm.te
41 index f4999e1b..bff2baa7 100644
42 --- a/policy/modules/system/lvm.te
43 +++ b/policy/modules/system/lvm.te
44 @@ -308,6 +308,7 @@ init_use_fds(lvm_t)
45 init_dontaudit_getattr_initctl(lvm_t)
46 init_use_script_ptys(lvm_t)
47 init_read_script_state(lvm_t)
48 +init_read_script_tmp_files(lvm_t)
49 # for systemd-cryptsetup to talk to /run/systemd/journal/socket
50 init_stream_connect(lvm_t)
51
52
53 diff --git a/policy/modules/system/sysnetwork.te b/policy/modules/system/sysnetwork.te
54 index 08f62ccd..ece5a301 100644
55 --- a/policy/modules/system/sysnetwork.te
56 +++ b/policy/modules/system/sysnetwork.te
57 @@ -375,6 +375,7 @@ ifdef(`hide_broken_symptoms',`
58
59 optional_policy(`
60 devicekit_read_pid_files(ifconfig_t)
61 + devicekit_append_inherited_log_files(ifconfig_t)
62 ')
63
64 optional_policy(`