Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/contrib/
Date: Sun, 30 Apr 2017 14:20:30
Message-Id: 1493561864.7529321be0c71a4426117c7cafcc2b952d9be90e.perfinion@gentoo
1 commit: 7529321be0c71a4426117c7cafcc2b952d9be90e
2 Author: Chris PeBenito <pebenito <AT> ieee <DOT> org>
3 AuthorDate: Wed Apr 19 01:34:54 2017 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Apr 30 14:17:44 2017 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=7529321b
7
8 some userdomain patches from Russell Coker
9
10 Added mono_run for unconfined and also xserver_role and allow it to dbus
11 chat with xdm.
12
13 Allow sysadm_t to read kmsg.
14
15 Allow user domains to dbus chat with kerneloops for the kerneloops desktop
16 gui. Also allow them to chat with devicekit disk and power daemons.
17
18 Allow gconfd_t to read /var/lib/gconf/defaults and /proc/filesystems
19
20 policy/modules/contrib/gnome.te | 8 +++++++-
21 1 file changed, 7 insertions(+), 1 deletion(-)
22
23 diff --git a/policy/modules/contrib/gnome.te b/policy/modules/contrib/gnome.te
24 index f69c10ba..25fe44da 100644
25 --- a/policy/modules/contrib/gnome.te
26 +++ b/policy/modules/contrib/gnome.te
27 @@ -1,4 +1,4 @@
28 -policy_module(gnome, 2.7.0)
29 +policy_module(gnome, 2.7.1)
30
31 ##############################
32 #
33 @@ -91,6 +91,12 @@ manage_dirs_pattern(gconfd_t, gconf_tmp_t, gconf_tmp_t)
34 manage_files_pattern(gconfd_t, gconf_tmp_t, gconf_tmp_t)
35 userdom_user_tmp_filetrans(gconfd_t, gconf_tmp_t, { dir file })
36
37 +# for /proc/filesystems
38 +kernel_read_system_state(gconfd_t)
39 +
40 +# for /var/lib/gconf/defaults
41 +files_read_var_lib_files(gconfd_t)
42 +
43 userdom_manage_user_tmp_dirs(gconfd_t)
44 userdom_tmp_filetrans_user_tmp(gconfd_t, dir)
45 userdom_user_runtime_filetrans_user_tmp(gconfd_t, dir)