aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSven Vermeulen <sven.vermeulen@siphos.be>2015-02-15 19:34:07 +0100
committerSven Vermeulen <sven.vermeulen@siphos.be>2015-02-15 19:34:07 +0100
commitb715e919f47327b139754f16e514d03ae3a46bb1 (patch)
treed14eccc4c1b85d644c90b7959aab51843eecdd3b
parentRemove duplicate mailman etc declaration (diff)
downloadhardened-refpolicy-b715e919f47327b139754f16e514d03ae3a46bb1.tar.gz
hardened-refpolicy-b715e919f47327b139754f16e514d03ae3a46bb1.tar.bz2
hardened-refpolicy-b715e919f47327b139754f16e514d03ae3a46bb1.zip
Fix bug #535986 - Mark configfs_t as file type/mount point
-rw-r--r--policy/modules/kernel/filesystem.te5
1 files changed, 5 insertions, 0 deletions
diff --git a/policy/modules/kernel/filesystem.te b/policy/modules/kernel/filesystem.te
index f78adef7..32ecb93c 100644
--- a/policy/modules/kernel/filesystem.te
+++ b/policy/modules/kernel/filesystem.te
@@ -306,3 +306,8 @@ allow filesystem_unconfined_type filesystem_type:filesystem *;
# pseudo filesystem types that are applied to both the filesystem
# and its files.
allow filesystem_unconfined_type filesystem_type:{ dir file lnk_file sock_file fifo_file chr_file blk_file } *;
+
+ifdef(`distro_gentoo',`
+ # Fix bug 535986 - Mark configfs_t as file type (and mountpoint probably as well)
+ files_mountpoint(configfs_t)
+')