1 |
commit: 76c8a52ec679ee5b1185eec8a09e59c2d94d3a09 |
2 |
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
3 |
AuthorDate: Sat Feb 23 12:14:55 2013 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Sat Feb 23 12:14:55 2013 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=76c8a52e |
7 |
|
8 |
emerge-webrsync reads in portage config |
9 |
|
10 |
The "emerge-webrsync" process uses portageq to get information about profile |
11 |
settings, thus requiring access to read/follow portage_conf_t links |
12 |
(/etc/portage/make.profile). |
13 |
|
14 |
--- |
15 |
policy/modules/contrib/portage.te | 1 + |
16 |
1 files changed, 1 insertions(+), 0 deletions(-) |
17 |
|
18 |
diff --git a/policy/modules/contrib/portage.te b/policy/modules/contrib/portage.te |
19 |
index 5f9f0b5..ffe46e3 100644 |
20 |
--- a/policy/modules/contrib/portage.te |
21 |
+++ b/policy/modules/contrib/portage.te |
22 |
@@ -366,6 +366,7 @@ ifdef(`distro_gentoo',` |
23 |
# Portage fetch local policy |
24 |
# |
25 |
|
26 |
+ read_lnk_files_pattern(portage_fetch_t, portage_conf_t, portage_conf_t) |
27 |
read_lnk_files_pattern(portage_fetch_t, portage_ebuild_t, portage_ebuild_t) |
28 |
|
29 |
dev_rw_autofs(portage_fetch_t) |