summaryrefslogtreecommitdiffstats
path: root/recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch
diff options
context:
space:
mode:
Diffstat (limited to 'recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch')
-rw-r--r--recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch38
1 files changed, 38 insertions, 0 deletions
diff --git a/recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch b/recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch
new file mode 100644
index 0000000..e5ad291
--- /dev/null
+++ b/recipes-security/refpolicy/refpolicy/0040-policy-modules-roles-sysadm-allow-sysadm-to-run-rpci.patch
@@ -0,0 +1,38 @@
1From 354389c93e26bb8d8e8c1c126b01d838a6a214c8 Mon Sep 17 00:00:00 2001
2From: Roy Li <rongqing.li@windriver.com>
3Date: Sat, 15 Feb 2014 09:45:00 +0800
4Subject: [PATCH] policy/modules/roles/sysadm: allow sysadm to run rpcinfo
5
6Fixes:
7$ rpcinfo
8rpcinfo: can't contact rpcbind: RPC: Remote system error - Permission denied
9
10avc: denied { connectto } for pid=406 comm="rpcinfo"
11path="/run/rpcbind.sock" scontext=root:sysadm_r:sysadm_t
12tcontext=system_u:system_r:rpcbind_t tclass=unix_stream_socket
13permissive=0
14
15Upstream-Status: Inappropriate [embedded specific]
16
17Signed-off-by: Roy Li <rongqing.li@windriver.com>
18Signed-off-by: Joe MacDonald <joe_macdonald@mentor.com>
19Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
20---
21 policy/modules/roles/sysadm.te | 1 +
22 1 file changed, 1 insertion(+)
23
24diff --git a/policy/modules/roles/sysadm.te b/policy/modules/roles/sysadm.te
25index f0370b426..fc0945fe4 100644
26--- a/policy/modules/roles/sysadm.te
27+++ b/policy/modules/roles/sysadm.te
28@@ -962,6 +962,7 @@ optional_policy(`
29 ')
30
31 optional_policy(`
32+ rpcbind_stream_connect(sysadm_t)
33 rpcbind_admin(sysadm_t, sysadm_r)
34 ')
35
36--
372.17.1
38