Skip to content
This repository has been archived by the owner on Sep 18, 2020. It is now read-only.

Commit

Permalink
sec-policy/selinux-*: Two small updates
Browse files Browse the repository at this point in the history
Ensure that containers can append to fifos so stderr works under Docker,
and quieten wake_alarm AVCs.
  • Loading branch information
Matthew Garrett committed Jan 13, 2017
1 parent 0be183d commit e97125f
Show file tree
Hide file tree
Showing 6 changed files with 3 additions and 2 deletions.
3 changes: 2 additions & 1 deletion sec-policy/selinux-base/files/kernel_mcs.diff
@@ -1,7 +1,7 @@
diff -ur refpolicy.orig/policy/modules/kernel/kernel.te refpolicy/policy/modules/kernel/kernel.te
--- refpolicy.orig/policy/modules/kernel/kernel.te 2015-06-24 14:05:01.160318849 -0700
+++ refpolicy/policy/modules/kernel/kernel.te 2015-06-24 14:06:23.468516424 -0700
@@ -442,3 +442,8 @@
@@ -442,3 +442,9 @@
#dev_manage_all_dev_nodes(kernel_t)
dev_setattr_generic_chr_files(kernel_t)
')
Expand All @@ -10,3 +10,4 @@ diff -ur refpolicy.orig/policy/modules/kernel/kernel.te refpolicy/policy/modules
+mcs_file_write_all(kernel_t)
+mcs_process_set_categories(kernel_t)
+mcs_ptrace_all(kernel_t)
+allow kernel_t self:capability2 wake_alarm;
2 changes: 1 addition & 1 deletion sec-policy/selinux-virt/files/virt.diff
Expand Up @@ -32,5 +32,5 @@ diff -u contrib.orig/virt.te contrib/virt.te
+allow svirt_lxc_net_t self:process getpgid;
+allow svirt_lxc_net_t svirt_lxc_file_t:file { entrypoint mounton };
+allow svirt_lxc_net_t var_lib_t:file { entrypoint execute execute_no_trans };
+allow svirt_lxc_net_t kernel_t:fifo_file { getattr ioctl read write open };
+allow svirt_lxc_net_t kernel_t:fifo_file { getattr ioctl read write open append };
+

0 comments on commit e97125f

Please sign in to comment.