1 |
commit: d3d524c7ff452197e596d9b3b07b799922d2d727 |
2 |
Author: Eduardo Barretto <ebarretto <AT> linux <DOT> vnet <DOT> ibm <DOT> com> |
3 |
AuthorDate: Wed Nov 29 13:27:18 2017 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Tue Dec 12 07:07:30 2017 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=d3d524c7 |
7 |
|
8 |
Update missing permissions for pkcs |
9 |
|
10 |
pkcsslotd needs access to tmpfs files and /etc/group file. |
11 |
|
12 |
Signed-off-by: Eduardo Barretto <ebarretto <AT> linux.vnet.ibm.com> |
13 |
|
14 |
policy/modules/contrib/pkcs.te | 4 +++- |
15 |
1 file changed, 3 insertions(+), 1 deletion(-) |
16 |
|
17 |
diff --git a/policy/modules/contrib/pkcs.te b/policy/modules/contrib/pkcs.te |
18 |
index 1ede749f..339b1176 100644 |
19 |
--- a/policy/modules/contrib/pkcs.te |
20 |
+++ b/policy/modules/contrib/pkcs.te |
21 |
@@ -54,10 +54,12 @@ files_tmp_filetrans(pkcs_slotd_t, pkcs_slotd_tmp_t, dir) |
22 |
|
23 |
manage_dirs_pattern(pkcs_slotd_t, pkcs_slotd_tmpfs_t, pkcs_slotd_tmpfs_t) |
24 |
manage_files_pattern(pkcs_slotd_t, pkcs_slotd_tmpfs_t, pkcs_slotd_tmpfs_t) |
25 |
-fs_tmpfs_filetrans(pkcs_slotd_t, pkcs_slotd_tmpfs_t, dir) |
26 |
+fs_tmpfs_filetrans(pkcs_slotd_t, pkcs_slotd_tmpfs_t, { dir file }) |
27 |
|
28 |
files_read_etc_files(pkcs_slotd_t) |
29 |
|
30 |
+auth_use_nsswitch(pkcs_slotd_t) |
31 |
+ |
32 |
logging_send_syslog_msg(pkcs_slotd_t) |
33 |
|
34 |
miscfiles_read_localization(pkcs_slotd_t) |