summaryrefslogtreecommitdiffstats
path: root/recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch
diff options
context:
space:
mode:
Diffstat (limited to 'recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch')
-rw-r--r--recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch31
1 files changed, 31 insertions, 0 deletions
diff --git a/recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch b/recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch
new file mode 100644
index 0000000..4f3253d
--- /dev/null
+++ b/recipes-security/refpolicy/refpolicy/0053-policy-modules-kernel-kernel-make-kernel_t-MLS-trust.patch
@@ -0,0 +1,31 @@
1From 35351cd7cb07622b5e43254b95d7801a5669358d Mon Sep 17 00:00:00 2001
2From: Yi Zhao <yi.zhao@windriver.com>
3Date: Thu, 31 Oct 2019 17:35:59 +0800
4Subject: [PATCH] policy/modules/kernel/kernel: make kernel_t MLS trusted for
5 writing to keys at all levels.
6
7Fixes:
8systemd-udevd[216]: regulatory.0: Process '/usr/sbin/crda' failed with exit code 254.
9
10Upstream-Status: Inappropriate [embedded specific]
11
12Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
13---
14 policy/modules/kernel/kernel.te | 1 +
15 1 file changed, 1 insertion(+)
16
17diff --git a/policy/modules/kernel/kernel.te b/policy/modules/kernel/kernel.te
18index b4b089823..5835d28b2 100644
19--- a/policy/modules/kernel/kernel.te
20+++ b/policy/modules/kernel/kernel.te
21@@ -384,6 +384,7 @@ mls_socket_write_all_levels(kernel_t)
22 mls_fd_use_all_levels(kernel_t)
23 # https://bugzilla.redhat.com/show_bug.cgi?id=667370
24 mls_file_downgrade(kernel_t)
25+mls_key_write_all_levels(kernel_t)
26
27 ifdef(`distro_redhat',`
28 # Bugzilla 222337
29--
302.25.1
31