From b87a437807f718d47a2fbb3d7ac807657fd4bfab Mon Sep 17 00:00:00 2001 From: Lukas Vrabec Date: Thu, 5 May 2016 10:54:35 +0200 Subject: [PATCH] Create new interface called systemd_login_filetrans_pid_files() --- docker-selinux.tgz | Bin 4317 -> 4317 bytes policy-rawhide-base.patch | 22 ++++++++++++++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/docker-selinux.tgz b/docker-selinux.tgz index 3e9a0650aeef90c07c06a919f30b99c864e281e1..c81c8fc9e674fb3e4b561bf10e7386fb8f17d472 100644 GIT binary patch delta 4292 zcmV;#5IgVPA>AP!ABzY8E($AG00Zq@>yO(u63yuZGAclGw_?Yn1J*Eiq3fB!7Fdc-m5tD!8agWy?qS4S%nd+Em7 z|D@OQ#f#uO+T?ju?|=ApOMV@1F~*=RfqY zf8q^6lx5|PBmpY}R!0R*aXK#0OO6WPmubOBy^dmX_PZEL2%T`|m#=KlQnh3w;U@$!7RT*PHf;yei{iRyS8uF~S{n}6%`%oC4Q6%?MRpN@_0p zV`}P?5-(SuFC$!+_J3-o14aBV5+$a5`9gkO$<{C=J~uv=`SSJZ;({ZKW`~*8K#wY9 zx{Ye`WW>xzGf~ijc7m9*lrmIcr<5g%{d;tEM)d1WHp8Htl>;P?W*{BDI*&*nEMn$wCPk+ot<$O?&W2Gea!|ase z9(*1i&(if5>&a}`#*(3JdW048nY_mn_m5!vz{-@XKS0J5UHM4K9=hnre~3u zs2T<$WoaDn8Mi(<*e;}t45L=n=^b{0lwWWKEo3>05J%y_$B30rrCf8%DkOrIIOZan z)0N;2<1C`o(|;9j>-V)Hvb$tXfB64%h__MxQTF|FRyV#WBB|BwiloJ6Qn!w0LfNlr zF|G57@J6kM)_-#Y|K7mAZ;$9m{rr!gp2AMRy^ktQX6yrXQ+TWj;LxeADo5$xIc~^B zNqu*CK4wtty&S=;Aa_q0$zzs{CuBZaH<}`4T*B>I2!FIhIztLtEJ%vvHOWf!nn5Zl zC<|{1Jk;( zrAJ2zY@#9wc6HkGc5{-$w)2&r&K-y(pQIel*c=6%2LeS2b%w-jfdzpjG2^MK*naLF z8(838k$(kq@@@?U{b74<%TTeqf>Y{liZ3B|6{9FcY(e?pr!7lG^&#HYp-}Z*2%R5C zuy~1>tc}9NuBZfznQKz8IpW2u-_3xSIm2{Ow;L#So`iCUDEWz^H}+&#vyRfRp`-Fy zx#4Q>0+bt+3vgTJ#9nB*P02lw&&RV_Vf(A#xqoQ50FLM9GZ84<3A-?OYc>wJ#Twyt zoTVUji2;JyfJ?;%LU9ihH?7L8}QZv%3qN?}30~5pZXhKw$c6FaTkc62ZTDxSPHNQ)*FKBlgUxXpc+5C+Okt(Z2o+*=O*0mY-nBj^G-ELP6i@SO=* z6$;l4j4F`x;}HdafK%ug_J5wxDAe-=_J1+0%OaoU2|U6=@e$6CTHLuLwR8gkjE9IF%8-XFVG%`=VdoCZC<4w zWR^j-#f$-oU$F~j_?_4J`!uHz!9I~Ueu_PQDIePX}srZsej^I z8PGzsSumCIKR4P(;@_7?O;ChU!?yA$zni7tEl;VOfsb@@{RpRSA97=whg6anFx`8H zorO8p@X8W{{TTTb6r-}Sl<|E38n;)&8~N%khd4~e!Hu{ZN}irA zfzuq@hZYL?L>)G+EHk}n%Q#e71Ap7g5j|@gaJ*r@5pgVBC%w$G4y&>$63UGTo^l+= znu~)P4L{e8x8s_gRy5|KnqXT#+yRE&Ju3DJQ*MJ|e&F%K23_x~5~d&=<&;VZemRAQ z?{%4xII1o^bq9Kkvr7GXu8n9E8T1yDOZaP-*8V9jnM-5j5&Iaa|9*eduYdo3dwp}N z|Nat}aP-5xOdys%6WZ`9xW2f$xSD07mM?;zNSwjrk3KRuCQEJv5<+8nVo}Mn3WBMB z@Lq!5mVk>>>ok4D?UTwA@Ms=F{a=6lIjG8->GOI(hJ!Ulw9=#38yr~3SHU{U zD1n(+=GkRm_(@+9k-RKIVSfr0qFvN|z7*{tZB~DTX%fcUsMru}&3Oc+88szZ!y&Sz z=_*Mcymcl$BjlGyjbY6>kwMpZ308|D1Y;z_HzubEQ#RD)XBqHr@6<&yMM9|5zfqJTMhHd zkO%xQ8F*u#VNE+M@Y7;K0*CC~E9OXdn2de@(#>zvSumY^l*$(9n`eD0i@!Z(6o-av ze`d8<4Epe^uWGt9ah_?DCJI(Q$^v0B;eI5K9i?MONw)p~9#6DNvy|93|ujP!h!SS(BQK^ zoSr)Pjs0u-(EY3vw9m=zK85%38uL~i2A|LE2ioNMpfp+3d4j=ZfFh0Ox-Rq9kfQmU zCPThicYjTl;eQb81Q|NnyB>u{f|AoC!O8PRf5ZMgWA20O)8;=i0=YXKfT7Bk4uDu? z51)x!nPoG7b3CrfW#>Briy1y6lhNnWz;b07lcJLj9=?XptW`BZ`Pk}iC#DoPOgmEu==Y7o? z%kC=>8yeF=W_hqme7cm!AaqIIfjARa%M0Tw{u@GY$yU#WOWD2t{W?}_(RcbuYNIL) zwd~uUWh5(u5hI{&$7_VP@UtM9JZcjeAb#Rz*aDLTLdRWM-wx97!~Z>vSwnk$C4b2PHb$GKsgemTtT5(B0a47-J5a*JgqK7Ko^Cb?uez6TqJ{RRv{a|FJWaJS z5_ad^Cb}hAW;5a>F{9^A3NAX*;cOBK-@A5D`=VEKVU=KaZj`5xG-d32(}^5YX7 z!o#nVkAc```Tb5h(w&b~q~c-eW;2~I{yc25soON{Cs#@|z^6_)uM@Mmp9Ye$ZGYvj zOF%B?x{V*li2D(zKgKeTnWV$g8aKaFvk|_~U0T88TdYf$+w<>+P!{rc1Uo0G29X?K zn1gzORd)DQio)SQIVimDSyOPA6l^`Ohv=Ll_DFgUwl2k5f(L4DE~cYqw7@VhkwC3x zZm1eSPFxMy9k&XsE^SzR;|>w~w|}#;to%%FM7c?;v8EJa1QdsRFPGuSTq?H@(Ia#1 z>TXIMj*pY-kh@1Jb{neRPwqoWRYDSPV*&ptiJLk#LKGK5ci@)iBR1fke*!H{;cu&n zuWfMrT1e8>ve(dVce-LarVH=6;`GPXQgEMbrZ30;P|mgiz06i!pN+?b=zossXn^fa z0^MG*{NBE=^c;A)L*}h=(4JN$&!#|=8{;1p2wAu9C7L$ygj#n1>>-7lmOI4HcZJW# zS5KepcATn~u4bYBrCzW$5Y=gv*PGA;!bA2}2^ge0vcwzxxUwY^B5NV-X*elW=6w>O zrJydKYE!jq3*Yf=fKfjzS${QDWef1Dc-7H#97Q1rZ`(%w7O^m*>>VrqaTU#R4!$d( zVe!x`Y)-6TmA^Y`xDq@A3S3wK`aF+^$j z%7L@;g?ow^m|6a{b$_T4eD0U$4wbX@US#Qc^7^z!`l{m`MrvL1*h;})TWrHWZ-D1` zfuZL+JF#U*0ng&sPITuOk&;`QrkDDrh=M6p0# z7v)`C(aT*!3B^zj=-@ZIq{@$Gr&{vO)h z@)8WZ1V6jH_{;fU7t?@r0j)rRJWI$fvhbe*pMjqAVdmLd88cmM!`d2*8g delta 4292 zcmV;#5IgVPA>AP!ABzY8J_9RP00Zq@>yO(u63r=3)le4ILGUcQtD_Z(y>w&k zf6{CD;zjTsZSp*-_doo)B|%w{;x#RsIwnC>RaqKGEG>&5E(;c=1*rp4Y~b_ayGzBk z1dwT0r#JYq`1?JH8%BbJtAAmT76IGpUrCumj~ATj(%=fdtD-u}gCfew_s<2@^B;QH zKkv=vh<8zqbgdkD&%rm>J%SG~y+9(v*RUdWPJwHkW`wFPB{diQ zF*Wr`iI=O-ml3W@dw(_4fg=7Fi4s%3d?CNCWNR1_pBo>`eEE8Halw&Av%}14php!l z-9|NeGGgYVnJ8#MJ3-7@N*OA!Q_2#>{yn-nBYatL`vBhQtJ+)BzwxIScTQT7I9;bC zk((#(dZcT)c!!Btb!0wp&wVU&c7QgxY}5n9>=5)nqaxanCx2$6az3cXu~HKIVRlM! z4?Yi%XX*Nj^<*||W697qJ;I9lOy1*(`$w>SU}ehHA0T6ju6(3q4_$QRzeoCA%CvNR6(j9VWaY!}i+hEc2P^bR{g$}hNr7P1^gh@)`eW5mj*Qm(mW6%s*99CH!P z=}Pd1aTZbP>3@p1_4`^8*zUDEt07s~g`Gk<{vTMbct3sawZ0q3qYR znAZ73c%xQB>%X~ye{bO5+ao$sKmX&Wr?3-n@1shS8T&xp6dtPrICQG3%2E1vjvI1O zQr{h(j~NtuFGnyd$lX&$@|b1g37L=9jiyK$mvFll0)H)$&X9r@3z8yvO|lZbW{^q> z%EDU$c`0VOa_drnS70f239gO6v7&?~RwzabVmlt6Al@~2{5E-KKUxCsUFo2W>FU7hy4-JImG?R@2@a|a^HCn<+BHb(*Hfk070ogpz>U_oF>%y_CQwx7Gl z1{SziWPib&yjw#-f7qVeGF0rY;FP+X;!DU~#VASF zZn)aJ0Obbd0^F84u@_oyQ*saF^YLs}*#0VbE`J&>faCf3Oauyd!Y&NnnvDZ)u|{|u zXDLWsVt`;a;8Jk`IZ?Re6hd|%cluWA;q6}q0!IG^z!Y!FPHISLfbOi*%>^m$j)S)? zDWk`O;$H4i&}u@e6BJ?8u&q4G?`A1@%Tp?6;3J(}Kf5~M9vp(NiXxP!>VkGgmNQ-ryR$z z=Hj46!_T$j?YO3=6^*&5CfJq_cYtAckBYs*l-r<~A9%d5LD&1LgeeF|Ii*s9UryoS zdtGKEj;c#f-GLtCtWv+8Ya<#(2EE1P68_qywSS6B=F%8>#6Cvqzu(_D>VLnl-=6Bf zzr-aR{V*>Rh^5bjHoOY1FRm`GX4$Cai{K{`XYlx=j|`5WRPwBXVCo;d zmteOg;NsLeO&@Xlr1Atjnuk#T*B^flsGu#PfH zU?!G%cG(wx(w9UeFN;u^LVty57j>U6MSDn_)gNJ+gz+{iHUwL99zkhFO^McUh-_)P zN|Fa}ok`CK`Q=e#So2McD(Yq5MfljiH$F>$=wS}e@HVeY(+&&#w3v{DW<{tv`Ur6RpxLW&7Y$5O2#}5!|L= z#@6r+5Z08iGzs$CqJK<+f-sQ|-3g9o`r#z$n4TpX@+Fz=#!a|nXP)k9gE zq{lkS)2`!9u;NcVZD>V`1njLpf-?=evz)WHq3F}3t|fC-7JtsYU~n0rNaMM#%e*zDX#S?j zkZ;!AUsGi`#D6+LhEDdbN8yp673MUvtK? z`wGN{#&nQb9;_0dF6A)@U6OYo&cxO7!nlh6h7eq`)pOxecCUZGj@4T9oqm$qs0u?Z z`}SuU$;x2F2x!~!8lf%xEJ!Ag+C&D3pST&ez$AgtaaY#2gEai`e@|nUQ3u5iG5qZ? zD;jS}GJk-L(WYstWI_uojQLSO6tnaWlrS;jB~gN>n@z&2?j@XPp}i?B)#)rxQ>~1I z-Fdf(Zb_Eej5tY*DtX|&fuD66hY*(&3q{dUi2eZcPSd9Asg!e2G1=*%=}Zul9W3WM7|@VN&$=}-hwxq&d}Pz zD1Tflj-JzvNz$PJQ-r}AkaYZ?l*Y!A^5k6lpU6(Eb6->!;B*8;8kS0{m5_DRWK8&3 z_Z_`4$%Ni?K=u?hFOi;FD5{iA8Au9lh|+Z*!BKQoS9#Y_JQw%GP*?VCi}a-%bPWno zX4EAL4@X)tJXo2-f`2~fPH2)pH^z^@mwzvU>^>GXoOoO`noUijIK*O(I!y>}t(!E# zj|%gn@Y&$cJ(U?%{I)7f#=pS+tG>!oMfAo;)1(quexQ(ff3jb`2li?nov5(<_(X^B z@ayDbAhub4zmtx1=OY!Vcv!mGOec3VZ2HVym9l@bl`sT0oY#BA=Tfuw9(`G4yY zkjuGl9DlM&F|D~gfDcLR`B>1>(b@+{JSBPh5Q}C&Pl34BnKGg zpk82=9e$Ofa5zv73a@+C6x<~RThHquI;V&|lHP-@OR<*Vfts6(>8KekFbqs2P^+06 zss@k~S3`Ektpck{8y4TVL&W~=tbZ&kKa(3#ZqjP3DTNpT#o^w|WjHdI%I!n+$XvU+ zn^K44r&Ydo^S*U-h7px6LbsFXMCNzQYkiAs`2C0rL@kT$cY{`VkT1a~uPD+(|pG0UW zsLQ9?RPEZrcYGUQ)DKHm4S!YH0{kjobu=AEQ3%4@wo$)DEQ~07$BKVkMRS~k?+R#G zJakDrn}CZbkK%1wbT(g6Kk4dYoz`RrYnQkO|I#axM(;lz586jva8JDun`G3A*kS?h%nTUL|71!@DaYtZy!%Vwh%O}$p{%E7qO6((&rNfO2Uy*oE)C#U4XomYDdQ5wE- z;H-S%o+1WjmVa#>YJUWu`{lVqNtmyT9-VwQt;On+wjjD;5lAk z==si0Y#9Z0Hxzn7k`$K6wwuAZB>$cw@~kC z3>_eiyj|jL7(P=v7}bBwbTG8{MlKLUz7D(|HrXn!?Dj zsyeDZ%!FjDrX5L{D!Q*-8vlQB37KE4AM?eA;rBnT-rT%-XTSgP_WkMa|9_F|5;NnM zzsZtK{vMV*0)IJ^J8Sbn{$a%WgM2_`wI{_lL@pazU#`;PQUWX%uU}6?k*^~oiUsnz zDDTRw$;oSBBd24U?>TE=@RB635C5U?ExvT8HTpT9!7ZGRxRV#h#|nsB$K5^Wf)8!UEY zg@~|oKXjI2)7N8bk$%HJkTqRrMzGL<05Ez4F!}egjyKawp|^AvV$W|fbPgykv-@}! zo~)rZQ8o_%@oE1hX47V2sW{H1w(YC`fOyIORM(@RqF;6dU_cY5;WzyIWb^U9_U?GP mPS@!=T^*va8ZT>k|g$)xT8cmM#IihIKV diff --git a/policy-rawhide-base.patch b/policy-rawhide-base.patch index 64e125d0..ea0417f8 100644 --- a/policy-rawhide-base.patch +++ b/policy-rawhide-base.patch @@ -46383,10 +46383,10 @@ index 0000000..0e4185f +/var/run/initramfs(/.*)? <> diff --git a/policy/modules/system/systemd.if b/policy/modules/system/systemd.if new file mode 100644 -index 0000000..3380372 +index 0000000..ebd6cc8 --- /dev/null +++ b/policy/modules/system/systemd.if -@@ -0,0 +1,1698 @@ +@@ -0,0 +1,1716 @@ +## SELinux policy for systemd components + +###################################### @@ -46679,6 +46679,24 @@ index 0000000..3380372 + + files_search_pids($1) + manage_files_pattern($1, systemd_logind_var_run_t, systemd_logind_var_run_t) ++') ++ ++ ++###################################### ++## ++## Read systemd_login PID files. ++## ++## ++## ++## Domain allowed access. ++## ++## ++# ++interface(`systemd_login_filetrans_pid_files',` ++ gen_require(` ++ type systemd_logind_var_run_t; ++ ') ++ + files_pid_filetrans($1, systemd_logind_var_run_t, file, "nologin") +') +