Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Tue, 13 Oct 2020 03:02:09
Message-Id: 1602450005.326c950e7b3c5e3ab77aff79f16e6440421f47ae.perfinion@gentoo
1 commit: 326c950e7b3c5e3ab77aff79f16e6440421f47ae
2 Author: Antoine Tenart <antoine.tenart <AT> bootlin <DOT> com>
3 AuthorDate: Mon Aug 31 13:38:13 2020 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Oct 11 21:00:05 2020 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=326c950e
7
8 udev: allow udevadm to retrieve xattrs
9
10 Fixes:
11
12 avc: denied { getattr } for pid=50 comm="udevadm" name="/" dev="vda"
13 ino=2 scontext=system_u:system_r:udevadm_t
14 tcontext=system_u:object_r:fs_t tclass=filesystem permissive=0
15
16 avc: denied { getattr } for pid=52 comm="udevadm" name="/" dev="vda"
17 ino=2 scontext=system_u:system_r:udevadm_t
18 tcontext=system_u:object_r:fs_t tclass=filesystem permissive=0
19
20 Signed-off-by: Antoine Tenart <antoine.tenart <AT> bootlin.com>
21 Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
22
23 policy/modules/system/udev.te | 2 ++
24 1 file changed, 2 insertions(+)
25
26 diff --git a/policy/modules/system/udev.te b/policy/modules/system/udev.te
27 index 49380fb2..2ef2337e 100644
28 --- a/policy/modules/system/udev.te
29 +++ b/policy/modules/system/udev.te
30 @@ -451,3 +451,5 @@ kernel_read_kernel_sysctls(udevadm_t)
31 kernel_read_system_state(udevadm_t)
32
33 seutil_read_file_contexts(udevadm_t)
34 +
35 +fs_getattr_xattr_fs(udevadm_t)