1 |
commit: cf50bf8d9c6b0227f0950146144ff53e4d25cd23 |
2 |
Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com> |
3 |
AuthorDate: Wed Nov 28 16:51:31 2012 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Wed Nov 28 20:20:20 2012 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=cf50bf8d |
7 |
|
8 |
Changes to the corosync policy module |
9 |
|
10 |
Sends to self with unix dgram socket |
11 |
|
12 |
Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com> |
13 |
|
14 |
--- |
15 |
policy/modules/contrib/corosync.te | 3 ++- |
16 |
1 files changed, 2 insertions(+), 1 deletions(-) |
17 |
|
18 |
diff --git a/policy/modules/contrib/corosync.te b/policy/modules/contrib/corosync.te |
19 |
index 904b241..78a58fa 100644 |
20 |
--- a/policy/modules/contrib/corosync.te |
21 |
+++ b/policy/modules/contrib/corosync.te |
22 |
@@ -1,4 +1,4 @@ |
23 |
-policy_module(corosync, 1.0.3) |
24 |
+policy_module(corosync, 1.0.4) |
25 |
|
26 |
######################################## |
27 |
# |
28 |
@@ -40,6 +40,7 @@ allow corosync_t self:process { setpgid setrlimit setsched signal signull }; |
29 |
allow corosync_t self:fifo_file rw_fifo_file_perms; |
30 |
allow corosync_t self:sem create_sem_perms; |
31 |
allow corosync_t self:shm create_shm_perms; |
32 |
+allow corosync_t self:unix_dgram_socket sendto; |
33 |
allow corosync_t self:unix_stream_socket { accept connectto listen }; |
34 |
|
35 |
manage_dirs_pattern(corosync_t, corosync_tmp_t, corosync_tmp_t) |