Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Fri, 06 Dec 2013 17:33:37
Message-Id: 1386351078.fc5282ecf2653a41bd13915c0b769f43291e1ab4.swift@gentoo
1 commit: fc5282ecf2653a41bd13915c0b769f43291e1ab4
2 Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com>
3 AuthorDate: Sat Nov 9 09:45:08 2013 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Fri Dec 6 17:31:18 2013 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=fc5282ec
7
8 libraries: for now i can only confirm mmap, might need to be changed to bin_t later if it turns out to need execute_no_trans
9
10 Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com>
11
12 ---
13 policy/modules/system/libraries.fc | 4 ++++
14 1 file changed, 4 insertions(+)
15
16 diff --git a/policy/modules/system/libraries.fc b/policy/modules/system/libraries.fc
17 index f9f8c2f..b019baf 100644
18 --- a/policy/modules/system/libraries.fc
19 +++ b/policy/modules/system/libraries.fc
20 @@ -118,6 +118,10 @@ ifdef(`distro_redhat',`
21
22 /usr/(.*/)?nvidia/.+\.so(\..*)? -- gen_context(system_u:object_r:textrel_shlib_t,s0)
23
24 +ifdef(`distro_debian',`
25 +/usr/(.*/)?dh-python/dh_pypy -- gen_context(system_u:object_r:lib_t,s0)
26 +')
27 +
28 /usr/lib/altivec/libavcodec\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0)
29 /usr/lib/cedega/.+\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0)
30 /usr/lib/dovecot/(.*/)?lib.*\.so.* -- gen_context(system_u:object_r:lib_t,s0)