Gentoo Archives: gentoo-commits

From: Sven Vermeulen <swift@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/kernel/
Date: Sun, 09 Feb 2014 10:54:59
Message-Id: 1391943162.e8474f760d33e29a5f8ae81215c33e44cc90d8a6.swift@gentoo
1 commit: e8474f760d33e29a5f8ae81215c33e44cc90d8a6
2 Author: Luis Ressel <aranea <AT> aixah <DOT> de>
3 AuthorDate: Sat Feb 1 13:50:24 2014 +0000
4 Commit: Sven Vermeulen <swift <AT> gentoo <DOT> org>
5 CommitDate: Sun Feb 9 10:52:42 2014 +0000
6 URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=e8474f76
7
8 Grant kernel_t necessary permissions for loopback mounts
9
10 For loopback mounts to work, the kernel requires access permissions to
11 fd's passed in by mount and to the source files (labeled mount_loopback_t).
12
13 ---
14 policy/modules/kernel/kernel.te | 3 +++
15 1 file changed, 3 insertions(+)
16
17 diff --git a/policy/modules/kernel/kernel.te b/policy/modules/kernel/kernel.te
18 index 1437180..c47eb45 100644
19 --- a/policy/modules/kernel/kernel.te
20 +++ b/policy/modules/kernel/kernel.te
21 @@ -287,6 +287,9 @@ files_list_etc(kernel_t)
22 files_list_home(kernel_t)
23 files_read_usr_files(kernel_t)
24
25 +mount_use_fds(kernel_t)
26 +mount_read_mount_loopback(kernel_t)
27 +
28 mcs_process_set_categories(kernel_t)
29
30 mls_process_read_up(kernel_t)