1 |
commit: 30716f76dddf7dfc3a415fefe35c9e3df3ceead5 |
2 |
Author: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
3 |
AuthorDate: Tue Dec 25 18:29:05 2012 +0000 |
4 |
Commit: Sven Vermeulen <sven.vermeulen <AT> siphos <DOT> be> |
5 |
CommitDate: Tue Dec 25 18:29:05 2012 +0000 |
6 |
URL: http://git.overlays.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=30716f76 |
7 |
|
8 |
Allow qemu to create TCP sockets (VNC support) |
9 |
|
10 |
To support binding to a VNC server (as well as GDB remote support), allow |
11 |
qemu_t to create a tcp_socket. |
12 |
|
13 |
--- |
14 |
policy/modules/contrib/qemu.te | 1 + |
15 |
1 files changed, 1 insertions(+), 0 deletions(-) |
16 |
|
17 |
diff --git a/policy/modules/contrib/qemu.te b/policy/modules/contrib/qemu.te |
18 |
index ebec831..d35858c 100644 |
19 |
--- a/policy/modules/contrib/qemu.te |
20 |
+++ b/policy/modules/contrib/qemu.te |
21 |
@@ -62,6 +62,7 @@ ifdef(`distro_gentoo',` |
22 |
# |
23 |
# Local policy |
24 |
# |
25 |
+ allow qemu_t self:tcp_socket create_stream_socket_perms; |
26 |
|
27 |
optional_policy(` |
28 |
vde_connect(qemu_t) |