summaryrefslogtreecommitdiffstats
path: root/recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch
diff options
context:
space:
mode:
Diffstat (limited to 'recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch')
-rw-r--r--recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch37
1 files changed, 0 insertions, 37 deletions
diff --git a/recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch b/recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch
deleted file mode 100644
index aa49ac7..0000000
--- a/recipes-security/refpolicy/refpolicy/0052-policy-modules-system-systemd-allow-systemd_logind_t.patch
+++ /dev/null
@@ -1,37 +0,0 @@
1From 5db5b20728dff6c5e75dc07ea4feb6c507661b62 Mon Sep 17 00:00:00 2001
2From: Yi Zhao <yi.zhao@windriver.com>
3Date: Wed, 8 Jul 2020 13:53:28 +0800
4Subject: [PATCH] policy/modules/system/systemd: allow systemd_logind_t to
5 watch initrc_runtime_t
6
7Fixes:
8avc: denied { watch } for pid=200 comm="systemd-logind"
9path="/run/utmp" dev="tmpfs" ino=12766
10scontext=system_u:system_r:systemd_logind_t:s0-s15:c0.c1023
11tcontext=system_u:object_r:initrc_runtime_t:s0 tclass=file permissive=0
12
13systemd-logind[200]: Failed to create inotify watch on /var/run/utmp, ignoring: Permission denied
14
15Upstream-Status: Inappropriate [embedded specific]
16
17Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
18---
19 policy/modules/system/systemd.te | 2 ++
20 1 file changed, 2 insertions(+)
21
22diff --git a/policy/modules/system/systemd.te b/policy/modules/system/systemd.te
23index 0411729ea..2d9d7d331 100644
24--- a/policy/modules/system/systemd.te
25+++ b/policy/modules/system/systemd.te
26@@ -651,6 +651,8 @@ init_stop_all_units(systemd_logind_t)
27 init_start_system(systemd_logind_t)
28 init_stop_system(systemd_logind_t)
29
30+allow systemd_logind_t initrc_runtime_t:file watch;
31+
32 locallogin_read_state(systemd_logind_t)
33
34 seutil_libselinux_linked(systemd_logind_t)
35--
362.17.1
37