1 |
commit: 1958d08d70d801a23e7ef15a8b3b0857b6c79946 |
2 |
Author: Daniel Burgener <Daniel.Burgener <AT> microsoft <DOT> com> |
3 |
AuthorDate: Wed Nov 11 21:14:43 2020 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Nov 28 22:55:41 2020 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=1958d08d |
7 |
|
8 |
Allow init to mount over the system bus |
9 |
|
10 |
In portable profiles, systemd bind mounts the system bus into process |
11 |
namespaces |
12 |
|
13 |
Signed-off-by: Daniel Burgener <Daniel.Burgener <AT> microsoft.com> |
14 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
15 |
|
16 |
policy/modules/services/dbus.te | 1 + |
17 |
1 file changed, 1 insertion(+) |
18 |
|
19 |
diff --git a/policy/modules/services/dbus.te b/policy/modules/services/dbus.te |
20 |
index f123c6d9..86e79b76 100644 |
21 |
--- a/policy/modules/services/dbus.te |
22 |
+++ b/policy/modules/services/dbus.te |
23 |
@@ -50,6 +50,7 @@ init_named_socket_activation(system_dbusd_t, system_dbusd_runtime_t) |
24 |
type system_dbusd_runtime_t alias system_dbusd_var_run_t; |
25 |
files_runtime_file(system_dbusd_runtime_t) |
26 |
init_daemon_runtime_file(system_dbusd_runtime_t, dir, "dbus") |
27 |
+init_mountpoint(system_dbusd_runtime_t) |
28 |
|
29 |
type system_dbusd_tmp_t; |
30 |
files_tmp_file(system_dbusd_tmp_t) |