[selinux-policy: 1529/3172] temporarily add unlabeled packet perm to unlabeled association if

Daniel J Walsh dwalsh at fedoraproject.org
Thu Oct 7 21:17:25 UTC 2010


commit c467d98e85276aa3ff53e92bf321877ed7e06381
Author: Chris PeBenito <cpebenito at tresys.com>
Date:   Wed Jun 28 14:54:04 2006 +0000

    temporarily add unlabeled packet perm to unlabeled association if

 refpolicy/policy/modules/kernel/kernel.if |    3 +++
 refpolicy/policy/modules/kernel/kernel.te |    2 +-
 2 files changed, 4 insertions(+), 1 deletions(-)
---
diff --git a/refpolicy/policy/modules/kernel/kernel.if b/refpolicy/policy/modules/kernel/kernel.if
index 599d8b8..230b601 100644
--- a/refpolicy/policy/modules/kernel/kernel.if
+++ b/refpolicy/policy/modules/kernel/kernel.if
@@ -2047,6 +2047,9 @@ interface(`kernel_sendrecv_unlabeled_association',`
 	')
 
 	allow $1 unlabeled_t:association { sendto recvfrom };
+
+	# temporary hack until labeling on packets is supported
+	allow $1 unlabeled_t:packet { send recv };
 ')
 
 ########################################
diff --git a/refpolicy/policy/modules/kernel/kernel.te b/refpolicy/policy/modules/kernel/kernel.te
index b58eb79..8b9d63d 100644
--- a/refpolicy/policy/modules/kernel/kernel.te
+++ b/refpolicy/policy/modules/kernel/kernel.te
@@ -1,5 +1,5 @@
 
-policy_module(kernel,1.3.11)
+policy_module(kernel,1.3.12)
 
 ########################################
 #


More information about the scm-commits mailing list