Re: [PATCH] Also label polkit-agent-helper-1 when installed directly in /usr/libexec

bauen1 <[email protected]>
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
Thanks,

See https://salsa.debian.org/utopia-team/polkit/-/commit/f6f99d85b2eb91bd03ca56d30837d7291711a0f8 for the change in the debian package.

On 7/22/20 10:59 AM, Laurent Bigonville wrote:
> From: Laurent Bigonville <[email protected]>
> 
> Debian now installs that executable directly in /usr/libexec for the
> version 0.105
> 
> Signed-off-by: Laurent Bigonville <[email protected]>
> ---
>  policy/modules/services/policykit.fc | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/policy/modules/services/policykit.fc b/policy/modules/services/policykit.fc
> index e2782838..85814b95 100644
> --- a/policy/modules/services/policykit.fc
> +++ b/policy/modules/services/policykit.fc
> @@ -11,6 +11,7 @@
>  # Systemd unit file
>  /usr/lib/systemd/system/[^/]*polkit.*	--	gen_context(system_u:object_r:policykit_unit_t,s0)
>  
> +/usr/libexec/polkit-agent-helper-1	--	gen_context(system_u:object_r:policykit_auth_exec_t,s0)

Since it is a debian only change, this should probably be wrapped in an ifdef distro_debian.

>  /usr/libexec/polkit-read-auth-helper	--	gen_context(system_u:object_r:policykit_auth_exec_t,s0)
>  /usr/libexec/polkit-grant-helper.*	--	gen_context(system_u:object_r:policykit_grant_exec_t,s0)
>  /usr/libexec/polkit-resolve-exe-helper.*	--	gen_context(system_u:object_r:policykit_resolve_exec_t,s0)
>
-- 
bauen1
https://dn42.bauen1.xyz/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.