summaryrefslogtreecommitdiffstats
path: root/recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch
diff options
context:
space:
mode:
Diffstat (limited to 'recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch')
-rw-r--r--recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch30
1 files changed, 30 insertions, 0 deletions
diff --git a/recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch b/recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch
new file mode 100644
index 0000000..5118ef8
--- /dev/null
+++ b/recipes-security/refpolicy/refpolicy/0054-policy-modules-system-setrans-allow-setrans_t-use-fd.patch
@@ -0,0 +1,30 @@
1From 6d6e2d34ec63771a01ef258c98f1ad49efdc2f67 Mon Sep 17 00:00:00 2001
2From: Roy Li <rongqing.li@windriver.com>
3Date: Sat, 22 Feb 2014 13:35:38 +0800
4Subject: [PATCH] policy/modules/system/setrans: allow setrans_t use fd at any
5 level
6
7Upstream-Status: Inappropriate [embedded specific]
8
9Signed-off-by: Roy Li <rongqing.li@windriver.com>
10Signed-off-by: Yi Zhao <yi.zhao@windriver.com>
11---
12 policy/modules/system/setrans.te | 2 ++
13 1 file changed, 2 insertions(+)
14
15diff --git a/policy/modules/system/setrans.te b/policy/modules/system/setrans.te
16index 12e66aad9..5510f7fac 100644
17--- a/policy/modules/system/setrans.te
18+++ b/policy/modules/system/setrans.te
19@@ -69,6 +69,8 @@ mls_net_receive_all_levels(setrans_t)
20 mls_socket_write_all_levels(setrans_t)
21 mls_process_read_all_levels(setrans_t)
22 mls_socket_read_all_levels(setrans_t)
23+mls_fd_use_all_levels(setrans_t)
24+mls_trusted_object(setrans_t)
25
26 selinux_compute_access_vector(setrans_t)
27
28--
292.25.1
30