1 |
commit: 7bc4fc00ec207bfb97c9baf00b87e0b03411c14d |
2 |
Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com> |
3 |
AuthorDate: Sat Nov 9 09:44:49 2013 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Fri Dec 6 17:31:02 2013 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=7bc4fc00 |
7 |
|
8 |
These { read write } tty_device_t chr files on boot up in Debian |
9 |
|
10 |
Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com> |
11 |
|
12 |
--- |
13 |
policy/modules/system/fstools.te | 5 +++++ |
14 |
policy/modules/system/hostname.te | 4 ++++ |
15 |
policy/modules/system/sysnetwork.te | 4 ++++ |
16 |
3 files changed, 13 insertions(+) |
17 |
|
18 |
diff --git a/policy/modules/system/fstools.te b/policy/modules/system/fstools.te |
19 |
index c7f82a3..4295d9c 100644 |
20 |
--- a/policy/modules/system/fstools.te |
21 |
+++ b/policy/modules/system/fstools.te |
22 |
@@ -149,6 +149,11 @@ seutil_read_config(fsadm_t) |
23 |
|
24 |
userdom_use_user_terminals(fsadm_t) |
25 |
|
26 |
+ifdef(`distro_debian',` |
27 |
+ term_dontaudit_use_unallocated_ttys(fsadm_t) |
28 |
+') |
29 |
+ |
30 |
+ |
31 |
ifdef(`distro_redhat',` |
32 |
optional_policy(` |
33 |
unconfined_domain(fsadm_t) |
34 |
|
35 |
diff --git a/policy/modules/system/hostname.te b/policy/modules/system/hostname.te |
36 |
index 24a7889..d5d4a1c 100644 |
37 |
--- a/policy/modules/system/hostname.te |
38 |
+++ b/policy/modules/system/hostname.te |
39 |
@@ -56,6 +56,10 @@ sysnet_dontaudit_rw_dhcpc_unix_stream_sockets(hostname_t) |
40 |
sysnet_read_config(hostname_t) |
41 |
sysnet_dns_name_resolve(hostname_t) |
42 |
|
43 |
+ifdef(`distro_debian',` |
44 |
+ term_dontaudit_use_unallocated_ttys(hostname_t) |
45 |
+') |
46 |
+ |
47 |
optional_policy(` |
48 |
nis_use_ypbind(hostname_t) |
49 |
') |
50 |
|
51 |
diff --git a/policy/modules/system/sysnetwork.te b/policy/modules/system/sysnetwork.te |
52 |
index 8bb0a25..7622852 100644 |
53 |
--- a/policy/modules/system/sysnetwork.te |
54 |
+++ b/policy/modules/system/sysnetwork.te |
55 |
@@ -329,6 +329,10 @@ sysnet_dontaudit_rw_dhcpc_udp_sockets(ifconfig_t) |
56 |
userdom_use_user_terminals(ifconfig_t) |
57 |
userdom_use_all_users_fds(ifconfig_t) |
58 |
|
59 |
+ifdef(`distro_debian',` |
60 |
+ term_dontaudit_use_unallocated_ttys(ifconfig_t) |
61 |
+') |
62 |
+ |
63 |
ifdef(`distro_ubuntu',` |
64 |
optional_policy(` |
65 |
unconfined_domain(ifconfig_t) |