Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/kernel/
Date: Wed, 29 Aug 2012 18:48:47
Message-Id: 1346263385.92db564a8296c2db25db7acdcc7d8fe9940c963f.SwifT@gentoo
1 commit: 92db564a8296c2db25db7acdcc7d8fe9940c963f
2 Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
3 AuthorDate: Wed Aug 29 18:03:05 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Wed Aug 29 18:03:05 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=92db564a
7
8 Merge with refpolicy / add lost+found filesystem labels to support NSA security guidelines from Guido Trentalancia
9
10 ---
11 policy/modules/kernel/files.fc | 6 ++++++
12 policy/modules/kernel/files.te | 2 +-
13 2 files changed, 7 insertions(+), 1 deletions(-)
14
15 diff --git a/policy/modules/kernel/files.fc b/policy/modules/kernel/files.fc
16 index dd95387..554f157 100644
17 --- a/policy/modules/kernel/files.fc
18 +++ b/policy/modules/kernel/files.fc
19 @@ -243,6 +243,12 @@ ifndef(`distro_redhat',`
20
21 /var/lock(/.*)? gen_context(system_u:object_r:var_lock_t,s0)
22
23 +/var/log/lost\+found -d gen_context(system_u:object_r:lost_found_t,mls_systemhigh)
24 +/var/log/lost\+found/.* <<none>>
25 +
26 +/var/log/audit/lost\+found -d gen_context(system_u:object_r:lost_found_t,mls_systemhigh)
27 +/var/log/audit/lost\+found/.* <<none>>
28 +
29 /var/lost\+found -d gen_context(system_u:object_r:lost_found_t,mls_systemhigh)
30 /var/lost\+found/.* <<none>>
31
32
33 diff --git a/policy/modules/kernel/files.te b/policy/modules/kernel/files.te
34 index 52ef84e..1f89fe2 100644
35 --- a/policy/modules/kernel/files.te
36 +++ b/policy/modules/kernel/files.te
37 @@ -1,4 +1,4 @@
38 -policy_module(files, 1.17.0)
39 +policy_module(files, 1.17.2)
40
41 ########################################
42 #