1 |
commit: 15298d9e66de9ec727e875e73e2d1560920b2e24 |
2 |
Author: Laurent Bigonville <bigon <AT> bigon <DOT> be> |
3 |
AuthorDate: Sun Nov 9 09:36:56 2014 +0000 |
4 |
Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> |
5 |
CommitDate: Sat Jan 30 17:02:52 2016 +0000 |
6 |
URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=15298d9e |
7 |
|
8 |
On Debian, systemd binaries are installed in / not /usr |
9 |
|
10 |
On Debian, systemd binaries are installed in / not /usr, add an |
11 |
equivalence for this. |
12 |
|
13 |
config/file_contexts.subs_dist | 1 + |
14 |
policy/modules/kernel/corecommands.fc | 2 +- |
15 |
2 files changed, 2 insertions(+), 1 deletion(-) |
16 |
|
17 |
diff --git a/config/file_contexts.subs_dist b/config/file_contexts.subs_dist |
18 |
index 7047ce7..84d8ada 100644 |
19 |
--- a/config/file_contexts.subs_dist |
20 |
+++ b/config/file_contexts.subs_dist |
21 |
@@ -1,4 +1,5 @@ |
22 |
/etc/init.d /etc/rc.d/init.d |
23 |
+/lib/systemd /usr/lib/systemd |
24 |
/lib32 /lib |
25 |
/lib64 /lib |
26 |
/run /var/run |
27 |
|
28 |
diff --git a/policy/modules/kernel/corecommands.fc b/policy/modules/kernel/corecommands.fc |
29 |
index b4e192a..8f12446 100644 |
30 |
--- a/policy/modules/kernel/corecommands.fc |
31 |
+++ b/policy/modules/kernel/corecommands.fc |
32 |
@@ -137,7 +137,6 @@ ifdef(`distro_debian',` |
33 |
/lib/nut/.* -- gen_context(system_u:object_r:bin_t,s0) |
34 |
/lib/readahead(/.*)? gen_context(system_u:object_r:bin_t,s0) |
35 |
/lib/security/pam_krb5/pam_krb5_storetmp -- gen_context(system_u:object_r:bin_t,s0) |
36 |
-/lib/systemd/systemd.* -- gen_context(system_u:object_r:bin_t,s0) |
37 |
/lib/udev/[^/]* -- gen_context(system_u:object_r:bin_t,s0) |
38 |
/lib/udev/scsi_id -- gen_context(system_u:object_r:bin_t,s0) |
39 |
/lib/upstart(/.*)? gen_context(system_u:object_r:bin_t,s0) |
40 |
@@ -242,6 +241,7 @@ ifdef(`distro_gentoo',` |
41 |
/usr/lib/rpm/rpmv -- gen_context(system_u:object_r:bin_t,s0) |
42 |
/usr/lib/sftp-server -- gen_context(system_u:object_r:bin_t,s0) |
43 |
/usr/lib/sudo/sesh -- gen_context(system_u:object_r:shell_exec_t,s0) |
44 |
+/usr/lib/systemd/systemd.* -- gen_context(system_u:object_r:bin_t,s0) |
45 |
/usr/lib/systemd/system-generators(/.*)? gen_context(system_u:object_r:bin_t,s0) |
46 |
/usr/lib/systemd/user-generators(/.*)? gen_context(system_u:object_r:bin_t,s0) |
47 |
/usr/lib/tumbler-1/tumblerd -- gen_context(system_u:object_r:bin_t,s0) |