Re: [PATCH] bind: add a few fc specs for unbound

Chris PeBenito <[email protected]>
Newsgroups org.kernel.vger.selinux-refpolicy
Message-ID <[email protected]>
On 9/9/20 6:00 AM, Dominick Grift wrote:
> unbound-checkconf is the unbound bind-checkconf equivalent
> unbound-control is the unbound bind ndc equivalent
> 
> Signed-off-by: Dominick Grift <[email protected]>
> ---
> These surfaced when I was helping someone on IRC to solve some issues. I figure I spent enough time on it for it to warrant a fix upstream.
> 
>   policy/modules/services/bind.fc | 4 ++++
>   1 file changed, 4 insertions(+)
> 
> diff --git a/policy/modules/services/bind.fc b/policy/modules/services/bind.fc
> index 7c1df489..ce68a0af 100644
> --- a/policy/modules/services/bind.fc
> +++ b/policy/modules/services/bind.fc
> @@ -19,6 +19,8 @@
>   /usr/bin/named-checkconf	--	gen_context(system_u:object_r:named_checkconf_exec_t,s0)
>   /usr/bin/r?ndc	--	gen_context(system_u:object_r:ndc_exec_t,s0)
>   /usr/bin/unbound	--	gen_context(system_u:object_r:named_exec_t,s0)
> +/usr/bin/unbound-checkconf	--	gen_context(system_u:object_r:named_checkconf_exec_t,s0)
> +/usr/bin/unbound-control	--	gen_context(system_u:object_r:ndc_exec_t,s0)
>   
>   /usr/lib/systemd/system/named.*\.service -- gen_context(system_u:object_r:named_unit_t,s0)
>   /usr/lib/systemd/system/unbound.*\.service -- gen_context(system_u:object_r:named_unit_t,s0)
> @@ -28,6 +30,8 @@
>   /usr/sbin/named-checkconf	--	gen_context(system_u:object_r:named_checkconf_exec_t,s0)
>   /usr/sbin/r?ndc	--	gen_context(system_u:object_r:ndc_exec_t,s0)
>   /usr/sbin/unbound	--	gen_context(system_u:object_r:named_exec_t,s0)
> +/usr/sbin/unbound-checkconf	--	gen_context(system_u:object_r:named_checkconf_exec_t,s0)
> +/usr/sbin/unbound-control	--	gen_context(system_u:object_r:ndc_exec_t,s0)
>   
>   /var/bind(/.*)?	gen_context(system_u:object_r:named_cache_t,s0)
>   /var/bind/pri(/.*)?	gen_context(system_u:object_r:named_zone_t,s0)

Merged.

-- 
Chris PeBenito
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.