Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Mon, 23 Jun 2014 19:58:26
Message-Id: 1403553444.7549d67ff17abac24b2cb5569cb278b26005b752.swift@gentoo
1 commit: 7549d67ff17abac24b2cb5569cb278b26005b752
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Mon Jun 23 19:57:24 2014 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Mon Jun 23 19:57:24 2014 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=7549d67f
7
8 Adding access interface to initrc_state_t
9
10 ---
11 policy/modules/system/init.if | 20 ++++++++++++++++++++
12 1 file changed, 20 insertions(+)
13
14 diff --git a/policy/modules/system/init.if b/policy/modules/system/init.if
15 index 62a86ec..4918397 100644
16 --- a/policy/modules/system/init.if
17 +++ b/policy/modules/system/init.if
18 @@ -1840,3 +1840,23 @@ interface(`init_udp_recvfrom_all_daemons',`
19 ')
20 corenet_udp_recvfrom_labeled($1, daemon)
21 ')
22 +
23 +## This should be behind a ifdef distro_gentoo but this is not allowed here
24 +
25 +#########################################
26 +## <summary>
27 +## Allow reading the init script state resources
28 +## </summary>
29 +## <param name="domain">
30 +## <summary>
31 +## Domain allowed access
32 +## </summary>
33 +## </param>
34 +#
35 +interface(`init_read_script_status_files',`
36 + gen_require(`
37 + type initrc_state_t;
38 + ')
39 +
40 + read_files_pattern($1, initrc_state_t, initrc_state_t)
41 +')