summaryrefslogtreecommitdiffstats
path: root/recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch
diff options
context:
space:
mode:
Diffstat (limited to 'recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch')
-rw-r--r--recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch36
1 files changed, 36 insertions, 0 deletions
diff --git a/recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch b/recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch
new file mode 100644
index 0000000..d545d2a
--- /dev/null
+++ b/recipes-security/refpolicy/refpolicy/0003-refpolicy-minimum-make-dbus-module-optional.patch
@@ -0,0 +1,36 @@
1From e28807393f105a16528cb5304283bde0b771fc4e Mon Sep 17 00:00:00 2001
2From: Yi Zhao <yi.zhao@windriver.com>
3Date: Wed, 9 Nov 2022 10:53:26 +0800
4Subject: [PATCH] refpolicy-minimum: make dbus module optional
5
6The mount module invokes interface
7dbus_dontaudit_write_system_bus_runtime_named_sockets which is from dbus
8module. Since dbus is not a core moudle in sysvinit system, we could
9make this interface optional in mount module by optional_policy. Then we
10could make the minimum policy without dbus module.
11
12Upstream-Status: Inappropriate [embedded specific]
13
14Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
15---
16 policy/modules/system/mount.te | 4 +++-
17 1 file changed, 3 insertions(+), 1 deletion(-)
18
19diff --git a/policy/modules/system/mount.te b/policy/modules/system/mount.te
20index 97f49e58e..b59529a01 100644
21--- a/policy/modules/system/mount.te
22+++ b/policy/modules/system/mount.te
23@@ -146,7 +146,9 @@ selinux_getattr_fs(mount_t)
24
25 userdom_use_all_users_fds(mount_t)
26
27-dbus_dontaudit_write_system_bus_runtime_named_sockets(mount_t)
28+optional_policy(`
29+ dbus_dontaudit_write_system_bus_runtime_named_sockets(mount_t)
30+')
31
32 ifdef(`distro_redhat',`
33 optional_policy(`
34--
352.25.1
36