Gentoo Archives: gentoo-commits

From: Jason Zaman <perfinion@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] proj/hardened-refpolicy:master commit in: policy/modules/kernel/, config/
Date: Sat, 30 Jan 2016 17:21:22
Message-Id: 1454173372.15298d9e66de9ec727e875e73e2d1560920b2e24.perfinion@gentoo
1 commit: 15298d9e66de9ec727e875e73e2d1560920b2e24
2 Author: Laurent Bigonville <bigon <AT> bigon <DOT> be>
3 AuthorDate: Sun Nov 9 09:36:56 2014 +0000
4 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org>
5 CommitDate: Sat Jan 30 17:02:52 2016 +0000
6 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=15298d9e
7
8 On Debian, systemd binaries are installed in / not /usr
9
10 On Debian, systemd binaries are installed in / not /usr, add an
11 equivalence for this.
12
13 config/file_contexts.subs_dist | 1 +
14 policy/modules/kernel/corecommands.fc | 2 +-
15 2 files changed, 2 insertions(+), 1 deletion(-)
16
17 diff --git a/config/file_contexts.subs_dist b/config/file_contexts.subs_dist
18 index 7047ce7..84d8ada 100644
19 --- a/config/file_contexts.subs_dist
20 +++ b/config/file_contexts.subs_dist
21 @@ -1,4 +1,5 @@
22 /etc/init.d /etc/rc.d/init.d
23 +/lib/systemd /usr/lib/systemd
24 /lib32 /lib
25 /lib64 /lib
26 /run /var/run
27
28 diff --git a/policy/modules/kernel/corecommands.fc b/policy/modules/kernel/corecommands.fc
29 index b4e192a..8f12446 100644
30 --- a/policy/modules/kernel/corecommands.fc
31 +++ b/policy/modules/kernel/corecommands.fc
32 @@ -137,7 +137,6 @@ ifdef(`distro_debian',`
33 /lib/nut/.* -- gen_context(system_u:object_r:bin_t,s0)
34 /lib/readahead(/.*)? gen_context(system_u:object_r:bin_t,s0)
35 /lib/security/pam_krb5/pam_krb5_storetmp -- gen_context(system_u:object_r:bin_t,s0)
36 -/lib/systemd/systemd.* -- gen_context(system_u:object_r:bin_t,s0)
37 /lib/udev/[^/]* -- gen_context(system_u:object_r:bin_t,s0)
38 /lib/udev/scsi_id -- gen_context(system_u:object_r:bin_t,s0)
39 /lib/upstart(/.*)? gen_context(system_u:object_r:bin_t,s0)
40 @@ -242,6 +241,7 @@ ifdef(`distro_gentoo',`
41 /usr/lib/rpm/rpmv -- gen_context(system_u:object_r:bin_t,s0)
42 /usr/lib/sftp-server -- gen_context(system_u:object_r:bin_t,s0)
43 /usr/lib/sudo/sesh -- gen_context(system_u:object_r:shell_exec_t,s0)
44 +/usr/lib/systemd/systemd.* -- gen_context(system_u:object_r:bin_t,s0)
45 /usr/lib/systemd/system-generators(/.*)? gen_context(system_u:object_r:bin_t,s0)
46 /usr/lib/systemd/user-generators(/.*)? gen_context(system_u:object_r:bin_t,s0)
47 /usr/lib/tumbler-1/tumblerd -- gen_context(system_u:object_r:bin_t,s0)