Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Sat, 30 Jan 2016 17:21:22
Message-Id: 1454173372.6b7f2fdba7706b4859e2d63c4b8ef887b61d6bbd.perfinion@gentoo
1 commit: 6b7f2fdba7706b4859e2d63c4b8ef887b61d6bbd
2 Author: Laurent Bigonville <bigon <AT> bigon <DOT> be>
3 AuthorDate: Wed Dec 16 18:19:30 2015 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sat Jan 30 17:02:52 2016 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=6b7f2fdb
7
8 Allow syslogd_t to read sysctl_vm_overcommit_t
9
10 policy/modules/system/logging.te | 3 ++-
11 1 file changed, 2 insertions(+), 1 deletion(-)
12
13 diff --git a/policy/modules/system/logging.te b/policy/modules/system/logging.te
14 index 7b6b6fb..f2e4984 100644
15 --- a/policy/modules/system/logging.te
16 +++ b/policy/modules/system/logging.te
17 @@ -418,7 +418,8 @@ kernel_read_kernel_sysctls(syslogd_t)
18 kernel_read_proc_symlinks(syslogd_t)
19 # Allow access to /proc/kmsg for syslog-ng
20 kernel_read_messages(syslogd_t)
21 -kernel_read_vm_sysctls(syslogd_t)
22 +# rsyslog
23 +kernel_read_vm_overcommit_sysctl(syslogd_t)
24 kernel_clear_ring_buffer(syslogd_t)
25 kernel_change_ring_buffer_level(syslogd_t)
26 # Read ring buffer for journald