1 |
commit: fc5282ecf2653a41bd13915c0b769f43291e1ab4 |
2 |
Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com> |
3 |
AuthorDate: Sat Nov 9 09:45:08 2013 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Fri Dec 6 17:31:18 2013 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=fc5282ec |
7 |
|
8 |
libraries: for now i can only confirm mmap, might need to be changed to bin_t later if it turns out to need execute_no_trans |
9 |
|
10 |
Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com> |
11 |
|
12 |
--- |
13 |
policy/modules/system/libraries.fc | 4 ++++ |
14 |
1 file changed, 4 insertions(+) |
15 |
|
16 |
diff --git a/policy/modules/system/libraries.fc b/policy/modules/system/libraries.fc |
17 |
index f9f8c2f..b019baf 100644 |
18 |
--- a/policy/modules/system/libraries.fc |
19 |
+++ b/policy/modules/system/libraries.fc |
20 |
@@ -118,6 +118,10 @@ ifdef(`distro_redhat',` |
21 |
|
22 |
/usr/(.*/)?nvidia/.+\.so(\..*)? -- gen_context(system_u:object_r:textrel_shlib_t,s0) |
23 |
|
24 |
+ifdef(`distro_debian',` |
25 |
+/usr/(.*/)?dh-python/dh_pypy -- gen_context(system_u:object_r:lib_t,s0) |
26 |
+') |
27 |
+ |
28 |
/usr/lib/altivec/libavcodec\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0) |
29 |
/usr/lib/cedega/.+\.so(\.[^/]*)* -- gen_context(system_u:object_r:textrel_shlib_t,s0) |
30 |
/usr/lib/dovecot/(.*/)?lib.*\.so.* -- gen_context(system_u:object_r:lib_t,s0) |