瀏覽代碼

portage_additional: allow read_crypto_sysctls and cap sys_resource

Helmut Pozimski 4 年之前
父節點
當前提交
4c3c785ab2
共有 1 個文件被更改,包括 5 次插入1 次删除
  1. 5 1
      portage_additional.te

+ 5 - 1
portage_additional.te

@@ -1,4 +1,4 @@
-policy_module(portage_additional, 0.0.3)
+policy_module(portage_additional, 0.0.4)
 
 require {
   type portage_fetch_t;
@@ -24,9 +24,13 @@ allow portage_fetch_t etc_t:file link;
 
 corenet_udp_bind_generic_node(portage_t)
 files_manage_etc_files(portage_t)
+kernel_read_crypto_sysctls(portage_t)
 allow portage_t self:process ptrace;
+allow portage_t self:capability sys_resource;
 allow portage_t unlabeled_t:file { execute execute_no_trans map relabelfrom relabelto };
 allow portage_t usr_t:file { execute execute_no_trans };
+allow portage_t etc_t:file { relabelfrom relabelto };
+
 
 
 allow portage_sandbox_t ldconfig_cache_t:file map;