Changeset 2691

Show
Ignore:
Timestamp:
05/22/08 13:39:03 (7 months ago)
Author:
pebenito
Message:

trunk: Module loading now requires setsched on kernel threads.

Files:

Legend:

Unmodified
Added
Removed
Modified
Copied
Moved
  • trunk/Changelog

    r2681 r2691  
     1- Module loading now requires setsched on kernel threads. 
    12- Patch to allow gpg agent --write-env-file option from Vaclav Ovsik. 
    23- X application data class from Eamon Walsh and Ted Toth. 
  • trunk/policy/modules/kernel/kernel.if

    r2659 r2691  
    331331        allow $1 self:capability sys_module; 
    332332        typeattribute $1 can_load_kernmodule; 
     333 
     334        # load_module() calls stop_machine() which 
     335        # calls sched_setscheduler() 
     336        allow $1 self:capability sys_nice; 
     337        kernel_setsched($1) 
    333338') 
    334339 
  • trunk/policy/modules/kernel/kernel.te

    r2659 r2691  
    11 
    2 policy_module(kernel,1.9.1
     2policy_module(kernel,1.9.2
    33 
    44######################################## 
  • trunk/policy/modules/services/networkmanager.te

    r2668 r2691  
    2121# networkmanager will ptrace itself if gdb is installed 
    2222# and it receives a unexpected signal (rh bug #204161)  
    23 allow NetworkManager_t self:capability { kill setgid setuid sys_nice dac_override net_admin net_raw net_bind_service ipc_lock }; 
     23allow NetworkManager_t self:capability { kill setgid setuid dac_override net_admin net_raw net_bind_service ipc_lock }; 
    2424dontaudit NetworkManager_t self:capability { sys_tty_config sys_ptrace }; 
    2525allow NetworkManager_t self:process { ptrace setcap setpgid getsched signal_perms };