Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Mon, 23 Jan 2017 18:17:38
Message-Id: 1485194655.bd9a0390dde045170e4291bbd5a0e8655d435b39.perfinion@gentoo
1 commit: bd9a0390dde045170e4291bbd5a0e8655d435b39
2 Author: Jason Zaman <jason <AT> perfinion <DOT> com>
3 AuthorDate: Mon Jan 23 18:04:15 2017 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Mon Jan 23 18:04:15 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=bd9a0390
7
8 sysnetwork: allow dhcpc scripts to run resolvconf
9
10 dhcpcd runs resolvconf from a script not directly from dhcpc_t
11
12 type=AVC msg=audit(1480827246.554:34865): avc: denied { open } for
13 pid=16908 comm="resolvconf" path="/proc/meminfo" dev="proc"
14 ino=4026531989 scontext=system_u:system_r:resolvconf_t
15 tcontext=system_u:object_r:proc_t tclass=file
16
17 Gentoo-Bug: https://bugs.gentoo.org/602624
18
19 policy/modules/system/sysnetwork.te | 4 ++++
20 1 file changed, 4 insertions(+)
21
22 diff --git a/policy/modules/system/sysnetwork.te b/policy/modules/system/sysnetwork.te
23 index 18090d0..c7fdcb9 100644
24 --- a/policy/modules/system/sysnetwork.te
25 +++ b/policy/modules/system/sysnetwork.te
26 @@ -493,4 +493,8 @@ ifdef(`distro_gentoo',`
27 optional_policy(`
28 ntp_manage_config(dhcpc_script_t)
29 ')
30 +
31 + optional_policy(`
32 + resolvconf_client_domain(dhcpc_script_t)
33 + ')
34 ')