From 27c570f755c4332b0bbb7f5a4bbe32db8f9b56de Mon Sep 17 00:00:00 2001 From: Chris PeBenito Date: Mon, 30 Apr 2007 14:44:04 +0000 Subject: [PATCH] trivial fix for netutils from dan --- policy/modules/admin/netutils.te | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/policy/modules/admin/netutils.te b/policy/modules/admin/netutils.te index 05d904c3..a7e9a1ef 100644 --- a/policy/modules/admin/netutils.te +++ b/policy/modules/admin/netutils.te @@ -1,5 +1,5 @@ -policy_module(netutils,1.4.0) +policy_module(netutils,1.4.1) ######################################## # @@ -40,6 +40,7 @@ role system_r types traceroute_t; # Perform network administration operations and have raw access to the network. allow netutils_t self:capability { net_admin net_raw setuid setgid }; +dontaudit netutils_t self:capability sys_tty_config; allow netutils_t self:process { sigkill sigstop signull signal }; allow netutils_t self:netlink_route_socket { bind create getattr nlmsg_read nlmsg_write read write }; allow netutils_t self:packet_socket create_socket_perms; @@ -132,6 +133,8 @@ libs_use_shared_libs(ping_t) logging_send_syslog_msg(ping_t) +miscfiles_read_localization(ping_t) + sysnet_read_config(ping_t) sysnet_dns_name_resolve(ping_t)