1 |
commit: 3a34bdec305591d9452b07c29d59c61a6c365d81 |
2 |
Author: Dominick Grift <dac.override <AT> gmail <DOT> com> |
3 |
AuthorDate: Thu Dec 10 16:08:27 2015 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Thu Dec 17 15:25:22 2015 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=3a34bdec |
7 |
|
8 |
kernel: implement sysctl_vm_overcommit_t for /proc/sys/vm/overcommit_memory |
9 |
|
10 |
Whoever requires this type first gets to create the interfaces to operate on this object |
11 |
|
12 |
Signed-off-by: Dominick Grift <dac.override <AT> gmail.com> |
13 |
|
14 |
policy/modules/kernel/kernel.te | 3 +++ |
15 |
1 file changed, 3 insertions(+) |
16 |
|
17 |
diff --git a/policy/modules/kernel/kernel.te b/policy/modules/kernel/kernel.te |
18 |
index 0de538c..2625e2f 100644 |
19 |
--- a/policy/modules/kernel/kernel.te |
20 |
+++ b/policy/modules/kernel/kernel.te |
21 |
@@ -153,6 +153,9 @@ genfscon proc /sys/net/unix gen_context(system_u:object_r:sysctl_net_unix_t,s0) |
22 |
type sysctl_vm_t, sysctl_type; |
23 |
genfscon proc /sys/vm gen_context(system_u:object_r:sysctl_vm_t,s0) |
24 |
|
25 |
+type sysctl_vm_overcommit_t, sysctl_type; |
26 |
+genfscon proc /sys/vm/overcommit_memory gen_context(system_u:object_r:sysctl_vm_overcommit_t,s0) |
27 |
+ |
28 |
# /proc/sys/dev directory and files |
29 |
type sysctl_dev_t, sysctl_type; |
30 |
genfscon proc /sys/dev gen_context(system_u:object_r:sysctl_dev_t,s0) |