Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/system/
Date: Tue, 13 Oct 2020 03:02:10
Message-Id: 1602450880.8ea2a42f1a0d9051533a8d262f5487f44fa605ae.perfinion@gentoo
1 commit: 8ea2a42f1a0d9051533a8d262f5487f44fa605ae
2 Author: Antoine Tenart <antoine.tenart <AT> bootlin <DOT> com>
3 AuthorDate: Thu Aug 13 09:52:20 2020 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sun Oct 11 21:14:40 2020 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=8ea2a42f
7
8 systemd: add extra systemd_generator_t rules
9
10 Fixes:
11
12 avc: denied { setfscreate } for pid=41 comm="systemd-getty-g"
13 scontext=system_u:system_r:systemd_generator_t
14 tcontext=system_u:system_r:systemd_generator_t tclass=process
15 permissive=1
16
17 avc: denied { dac_override } for pid=40 comm="systemd-fstab-g"
18 capability=1 scontext=system_u:system_r:systemd_generator_t
19 tcontext=system_u:system_r:systemd_generator_t tclass=capability
20 permissive=1
21
22 Signed-off-by: Antoine Tenart <antoine.tenart <AT> bootlin.com>
23 Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org>
24
25 policy/modules/system/systemd.te | 2 ++
26 1 file changed, 2 insertions(+)
27
28 diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te
29 index 14306447..d0a852a2 100644
30 --- a/policy/modules/system/systemd.te
31 +++ b/policy/modules/system/systemd.te
32 @@ -362,6 +362,8 @@ seutil_search_default_contexts(systemd_coredump_t)
33 #
34
35 allow systemd_generator_t self:fifo_file rw_fifo_file_perms;
36 +allow systemd_generator_t self:capability dac_override;
37 +allow systemd_generator_t self:process setfscreate;
38
39 corecmd_getattr_bin_files(systemd_generator_t)