commit: 8ea2a42f1a0d9051533a8d262f5487f44fa605ae Author: Antoine Tenart <antoine.tenart <AT> bootlin <DOT> com> AuthorDate: Thu Aug 13 09:52:20 2020 +0000 Commit: Jason Zaman <perfinion <AT> gentoo <DOT> org> CommitDate: Sun Oct 11 21:14:40 2020 +0000 URL: https://gitweb.gentoo.org/proj/hardened-refpolicy.git/commit/?id=8ea2a42f
systemd: add extra systemd_generator_t rules Fixes: avc: denied { setfscreate } for pid=41 comm="systemd-getty-g" scontext=system_u:system_r:systemd_generator_t tcontext=system_u:system_r:systemd_generator_t tclass=process permissive=1 avc: denied { dac_override } for pid=40 comm="systemd-fstab-g" capability=1 scontext=system_u:system_r:systemd_generator_t tcontext=system_u:system_r:systemd_generator_t tclass=capability permissive=1 Signed-off-by: Antoine Tenart <antoine.tenart <AT> bootlin.com> Signed-off-by: Jason Zaman <perfinion <AT> gentoo.org> policy/modules/system/systemd.te | 2 ++ 1 file changed, 2 insertions(+) diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te index 14306447..d0a852a2 100644 --- a/policy/modules/system/systemd.te +++ b/policy/modules/system/systemd.te @@ -362,6 +362,8 @@ seutil_search_default_contexts(systemd_coredump_t) # allow systemd_generator_t self:fifo_file rw_fifo_file_perms; +allow systemd_generator_t self:capability dac_override; +allow systemd_generator_t self:process setfscreate; corecmd_getattr_bin_files(systemd_generator_t)