1 |
commit: e8474f760d33e29a5f8ae81215c33e44cc90d8a6 |
2 |
Author: Luis Ressel <aranea <AT> aixah <DOT> de> |
3 |
AuthorDate: Sat Feb 1 13:50:24 2014 +0000 |
4 |
Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Feb 9 10:52:42 2014 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=e8474f76 |
7 |
|
8 |
Grant kernel_t necessary permissions for loopback mounts |
9 |
|
10 |
For loopback mounts to work, the kernel requires access permissions to |
11 |
fd's passed in by mount and to the source files (labeled mount_loopback_t). |
12 |
|
13 |
--- |
14 |
policy/modules/kernel/kernel.te | 3 +++ |
15 |
1 file changed, 3 insertions(+) |
16 |
|
17 |
diff --git a/policy/modules/kernel/kernel.te b/policy/modules/kernel/kernel.te |
18 |
index 1437180..c47eb45 100644 |
19 |
--- a/policy/modules/kernel/kernel.te |
20 |
+++ b/policy/modules/kernel/kernel.te |
21 |
@@ -287,6 +287,9 @@ files_list_etc(kernel_t) |
22 |
files_list_home(kernel_t) |
23 |
files_read_usr_files(kernel_t) |
24 |
|
25 |
+mount_use_fds(kernel_t) |
26 |
+mount_read_mount_loopback(kernel_t) |
27 |
+ |
28 |
mcs_process_set_categories(kernel_t) |
29 |
|
30 |
mls_process_read_up(kernel_t) |