[refpolicy] [PATCH 1/1] Mount output should be writeable to puppet_tmp_t

Sven Vermeulen sven.vermeulen at siphos.be
Sat Sep 24 08:56:58 CDT 2011


When using puppet to configure systems, the puppet system
runs the mount command and captures its output in a temporary
file in /tmp (which is labeled puppet_tmp_t).

Signed-off-by: Sven Vermeulen <sven.vermeulen at siphos.be>
---
 policy/modules/system/mount.te |    4 ++++
 1 files changed, 4 insertions(+), 0 deletions(-)

diff --git a/policy/modules/system/mount.te b/policy/modules/system/mount.te
index 1284081..ca9cdc0 100644
--- a/policy/modules/system/mount.te
+++ b/policy/modules/system/mount.te
@@ -191,6 +191,10 @@ optional_policy(`
 	')
 ')
 
+optional_policy(`
+	puppet_rw_tmp(mount_t)
+')
+
 # for kernel package installation
 optional_policy(`
 	rpm_rw_pipes(mount_t)
-- 
1.7.3.4



More information about the refpolicy mailing list