1 |
commit: 8ea2a42f1a0d9051533a8d262f5487f44fa605ae |
2 |
Author: Antoine Tenart <antoine.tenart <AT> bootlin <DOT> com> |
3 |
AuthorDate: Thu Aug 13 09:52:20 2020 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Oct 11 21:14:40 2020 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=8ea2a42f |
7 |
|
8 |
systemd: add extra systemd_generator_t rules |
9 |
|
10 |
Fixes: |
11 |
|
12 |
avc: denied { setfscreate } for pid=41 comm="systemd-getty-g" |
13 |
scontext=system_u:system_r:systemd_generator_t |
14 |
tcontext=system_u:system_r:systemd_generator_t tclass=process |
15 |
permissive=1 |
16 |
|
17 |
avc: denied { dac_override } for pid=40 comm="systemd-fstab-g" |
18 |
capability=1 scontext=system_u:system_r:systemd_generator_t |
19 |
tcontext=system_u:system_r:systemd_generator_t tclass=capability |
20 |
permissive=1 |
21 |
|
22 |
Signed-off-by: Antoine Tenart <antoine.tenart <AT> bootlin.com> |
23 |
Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> |
24 |
|
25 |
policy/modules/system/systemd.te | 2 ++ |
26 |
1 file changed, 2 insertions(+) |
27 |
|
28 |
diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te |
29 |
index 14306447..d0a852a2 100644 |
30 |
--- a/policy/modules/system/systemd.te |
31 |
+++ b/policy/modules/system/systemd.te |
32 |
@@ -362,6 +362,8 @@ seutil_search_default_contexts(systemd_coredump_t) |
33 |
# |
34 |
|
35 |
allow systemd_generator_t self:fifo_file rw_fifo_file_perms; |
36 |
+allow systemd_generator_t self:capability dac_override; |
37 |
+allow systemd_generator_t self:process setfscreate; |
38 |
|
39 |
corecmd_getattr_bin_files(systemd_generator_t) |