1 |
commit: b3f7bbec02352eb175391b51119180bad035b096 |
2 |
Author: Jonathan Davies <jpds <AT> protonmail <DOT> com> |
3 |
AuthorDate: Tue Nov 17 15:58:31 2020 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Nov 29 01:32:30 2020 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=b3f7bbec |
7 |
|
8 |
portage.te: Allow portage_fetch_t to read /dev/urandom through interface. |
9 |
|
10 |
Closes: https://github.com/perfinion/hardened-refpolicy/pull/3 |
11 |
Signed-off-by: Jonathan Davies <jpds <AT> protonmail.com> |
12 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
13 |
|
14 |
policy/modules/admin/portage.te | 1 + |
15 |
1 file changed, 1 insertion(+) |
16 |
|
17 |
diff --git a/policy/modules/admin/portage.te b/policy/modules/admin/portage.te |
18 |
index c0d6cace..8e9865e2 100644 |
19 |
--- a/policy/modules/admin/portage.te |
20 |
+++ b/policy/modules/admin/portage.te |
21 |
@@ -303,6 +303,7 @@ corenet_udp_bind_generic_node(portage_fetch_t) |
22 |
corenet_udp_bind_all_unreserved_ports(portage_fetch_t) |
23 |
|
24 |
dev_read_rand(portage_fetch_t) |
25 |
+dev_read_urand(portage_fetch_t) |
26 |
|
27 |
domain_use_interactive_fds(portage_fetch_t) |