1 |
commit: f312afbcbc2ca62b7745e95fbe065c1f60ff28f5 |
2 |
Author: Chris PeBenito <pebenito <AT> ieee <DOT> org> |
3 |
AuthorDate: Tue Feb 2 19:02:49 2021 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Feb 6 21:15:09 2021 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=f312afbc |
7 |
|
8 |
systemd: Fix lint errors. |
9 |
|
10 |
Signed-off-by: Chris PeBenito <pebenito <AT> ieee.org> |
11 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
12 |
|
13 |
policy/modules/system/systemd.if | 5 ++--- |
14 |
1 file changed, 2 insertions(+), 3 deletions(-) |
15 |
|
16 |
diff --git a/policy/modules/system/systemd.if b/policy/modules/system/systemd.if |
17 |
index d7d0eb3d..48a63cb3 100644 |
18 |
--- a/policy/modules/system/systemd.if |
19 |
+++ b/policy/modules/system/systemd.if |
20 |
@@ -30,7 +30,6 @@ template(`systemd_role_template',` |
21 |
attribute systemd_user_session_type, systemd_log_parse_env_type; |
22 |
type systemd_user_runtime_t, systemd_user_runtime_notify_t; |
23 |
type systemd_run_exec_t, systemd_analyze_exec_t; |
24 |
- type systemd_machined_t; |
25 |
') |
26 |
|
27 |
################################# |
28 |
@@ -68,7 +67,7 @@ template(`systemd_role_template',` |
29 |
|
30 |
# Allow using file descriptors for user environment generators |
31 |
allow $3 $1_systemd_t:fd use; |
32 |
- allow $3 $1_systemd_t:fifo_file rw_inherited_file_perms; |
33 |
+ allow $3 $1_systemd_t:fifo_file rw_inherited_fifo_file_perms; |
34 |
|
35 |
# systemctl --user |
36 |
stream_connect_pattern($3, systemd_user_runtime_t, systemd_user_runtime_t, $1_systemd_t) |
37 |
@@ -1351,5 +1350,5 @@ interface(`systemd_use_machined_devpts', ` |
38 |
') |
39 |
|
40 |
allow $1 systemd_machined_t:fd use; |
41 |
- allow $1 systemd_machined_devpts_t:chr_file { read write }; |
42 |
+ allow $1 systemd_machined_devpts_t:chr_file rw_inherited_term_perms; |
43 |
') |