Gentoo Archives: gentoo-commits

From: Sven Vermeulen <sven.vermeulen@××××××.be>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/admin/
Date: Tue, 30 Oct 2012 20:25:36
Message-Id: 1351628271.282cb7cd1fd6546303dd0d0dea9e415f86f94008.SwifT@gentoo
1 commit: 282cb7cd1fd6546303dd0d0dea9e415f86f94008
2 Author: Dominick Grift <dominick.grift <AT> gmail <DOT> com>
3 AuthorDate: Wed Oct 24 12:45:57 2012 +0000
4 Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be>
5 CommitDate: Tue Oct 30 20:17:51 2012 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=282cb7cd
7
8 Arping needs setcap to cap_set_proc
9
10 rhbz#869615
11
12 Signed-off-by: Dominick Grift <dominick.grift <AT> gmail.com>
13
14 ---
15 policy/modules/admin/netutils.te | 2 +-
16 1 files changed, 1 insertions(+), 1 deletions(-)
17
18 diff --git a/policy/modules/admin/netutils.te b/policy/modules/admin/netutils.te
19 index e0791b9..7bd6d5c 100644
20 --- a/policy/modules/admin/netutils.te
21 +++ b/policy/modules/admin/netutils.te
22 @@ -35,7 +35,7 @@ init_system_domain(traceroute_t, traceroute_exec_t)
23 # Perform network administration operations and have raw access to the network.
24 allow netutils_t self:capability { net_admin net_raw setuid setgid };
25 dontaudit netutils_t self:capability sys_tty_config;
26 -allow netutils_t self:process signal_perms;
27 +allow netutils_t self:process { setcap signal_perms };
28 allow netutils_t self:netlink_route_socket create_netlink_socket_perms;
29 allow netutils_t self:packet_socket create_socket_perms;
30 allow netutils_t self:udp_socket create_socket_perms;