commit: bd9a0390dde045170e4291bbd5a0e8655d435b39 Author: Jason Zaman <jason <AT> perfinion <DOT> com> AuthorDate: Mon Jan 23 18:04:15 2017 +0000 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> CommitDate: Mon Jan 23 18:04:15 2017 +0000 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=bd9a0390
sysnetwork: allow dhcpc scripts to run resolvconf dhcpcd runs resolvconf from a script not directly from dhcpc_t type=AVC msg=audit(1480827246.554:34865): avc: denied { open } for pid=16908 comm="resolvconf" path="/proc/meminfo" dev="proc" ino=4026531989 scontext=system_u:system_r:resolvconf_t tcontext=system_u:object_r:proc_t tclass=file Gentoo-Bug: https://bugs.gentoo.org/602624 policy/modules/system/sysnetwork.te | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/policy/modules/system/sysnetwork.te b/policy/modules/system/sysnetwork.te index 18090d0..c7fdcb9 100644 --- a/policy/modules/system/sysnetwork.te +++ b/policy/modules/system/sysnetwork.te @@ -493,4 +493,8 @@ ifdef(`distro_gentoo',` optional_policy(` ntp_manage_config(dhcpc_script_t) ') + + optional_policy(` + resolvconf_client_domain(dhcpc_script_t) + ') ')