Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:next commit in: policy/modules/contrib/
Date: Sun, 10 Sep 2017 14:04:00
Message-Id: 1505049605.9f5bef71012d46627f45471c31aaf2928447359f.perfinion@gentoo
1 commit: 9f5bef71012d46627f45471c31aaf2928447359f
2 Author: Jason Zaman <jason <AT> perfinion <DOT> com>
3 AuthorDate: Sun Sep 10 13:20:05 2017 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Sep 10 13:20:05 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=9f5bef71
7
8 cgmanager: use nsswitch
9
10 cgmanager looks up usernames. the nsswitch interface will allow file map
11 for /etc/passwd.
12
13 policy/modules/contrib/cgmanager.te | 2 ++
14 1 file changed, 2 insertions(+)
15
16 diff --git a/policy/modules/contrib/cgmanager.te b/policy/modules/contrib/cgmanager.te
17 index c3cc5217..2674193f 100644
18 --- a/policy/modules/contrib/cgmanager.te
19 +++ b/policy/modules/contrib/cgmanager.te
20 @@ -40,6 +40,8 @@ allow cgmanager_t cgmanager_run_t:dir mounton;
21 kernel_domtrans_to(cgmanager_t, cgmanager_exec_t)
22 kernel_read_system_state(cgmanager_t)
23
24 +auth_use_nsswitch(cgmanager_t)
25 +
26 corecmd_exec_bin(cgmanager_t)
27
28 domain_read_all_domains_state(cgmanager_t)