Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp7251274ybi; Mon, 8 Jul 2019 17:56:10 -0700 (PDT) X-Google-Smtp-Source: APXvYqzIgQm2wokMR0qNdCWPm24BF88lFVHVaYBStbwEvZy1WcUi2K0VaX8c2CSLwA3gnq9nMzvM X-Received: by 2002:a63:374a:: with SMTP id g10mr26804797pgn.31.1562633770182; Mon, 08 Jul 2019 17:56:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1562633770; cv=none; d=google.com; s=arc-20160816; b=suNHqs99zJVMJNBLHCnDBI5dJsUe4QlfUnPIAOn8lJRF90kDuCHl47kajn7NJCvkWq ayp12mS2/lJEJzj0pT7XOn5KKkC5LP9UuQ2spJUFGro5a0rmmEBz9rmnVIdq2XEtzBOs WBmKn/k9ii+B6tDz9TCXWZ2l3XmPzedKNO8FSoJMk1xOGGi6IL8OIJ87NXVGzNwBjbo8 cKvBx+Rb4pp9cc2c+kuwJ+Cv5lNQ85CbnOF6Y8clVTkRqyF2FQbCd0HbxCLJhEAHRsDs G1QVfpi34mpiCFotNVZaPa/ZrTvuMqbkznFP/UhoiALcEpGqrrEZzBPWhEdH00D4Wb4m BYvA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:from:references:to:subject:dkim-signature; bh=XDs0LeowNdCYFTz1AC+j3jVCuI/Mjnoss5Bjx8NovP8=; b=yo2DZXa7fW/WBMYGnLcfDtLRHQ6LYaJOYFtQGzHqYadwg/ixpc901HQAatmEzGmEpH H8tA70R3IjCDk6Fb6dmPb8O+p0gnYWJaHWxsdw2op+y3h39W41/4zC33uC1oUBX+bdxG cjoKxjlHhkpVvU2EYz8A/pbjQoclDYd/QBgYa/TAuJhyEn/8HzStNxmZJmpGGARlENdQ cVmNyaBzymKBWDAluAp6AlqUW4qTOPqCq7bnTlu1kq/NyVYDYOQM/++BtO/+ZlQVPHsd h7T5qrTeqaeAHKzhdBIVufF4Rni+vad7KfjiT5cDW0BTJJFL4aA8EVSzNBAYaFzEEA6h RS1g== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=fssyAUg8; spf=pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id 73si9541307pfa.123.2019.07.08.17.56.08; Mon, 08 Jul 2019 17:56:10 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@ieee.org header.s=google header.b=fssyAUg8; spf=pass (google.com: best guess record for domain of selinux-refpolicy-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=ieee.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727143AbfGIAt6 (ORCPT + 11 others); Mon, 8 Jul 2019 20:49:58 -0400 Received: from mail-qk1-f193.google.com ([209.85.222.193]:42918 "EHLO mail-qk1-f193.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725857AbfGIAt5 (ORCPT ); Mon, 8 Jul 2019 20:49:57 -0400 Received: by mail-qk1-f193.google.com with SMTP id 201so12647645qkm.9 for ; Mon, 08 Jul 2019 17:49:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ieee.org; s=google; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language:content-transfer-encoding; bh=XDs0LeowNdCYFTz1AC+j3jVCuI/Mjnoss5Bjx8NovP8=; b=fssyAUg8XJlvk08X+uQoYiABHRGSMZnBIWUV3qiKqYyTpb9TBbkLRfCS9lTzxrtjUX v98RfKzO3rn277756oF5Iq1Af4p7qtXhmiV5ku8WLnZWnJpbymYDpxCUTXZJoIs9otjv bbbcukXONe7pRxDMiv33RxaNvbBBP/kT0+0Qw= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=XDs0LeowNdCYFTz1AC+j3jVCuI/Mjnoss5Bjx8NovP8=; b=Zb93qJxmUzD6HzvxJ5NMgo6UglU5rvjVWPTZ/MNLkmYsf3cfITviwXpnd+I6DG8/M2 x56Ld4jmwKSXMQeResbC1vhbA9/p4K1ihC4HrYx+p56k4hXFs+cJnP0hzOMZ81/fndxG MxrJaET9Ml5Vq6r/oLAMi6rHYlPWaokSAac9cBAVy1uJszLOiEmtiud/BRzuFYj7/CvV XOLgUlxArmTfk1JcbUmYKBve5BX9HswExAnGaLwZFCts1LTW5j5OtUkG8kI4xKeuLVYj jxObIPqduvSNj2KPZo+qjPMp1x1Tc13eZhzMcSl7lbdrxyKec5JWSAW6SIfrszdKl0U9 nCqQ== X-Gm-Message-State: APjAAAXFQ5vvycaX4MYUWPB6DM7+ooVFTNuk4AZ+H2KwjZd8wqPNq/Ca tb3mfX94dOA6ai/Id+5YcYaf5bmeXfw= X-Received: by 2002:a05:620a:10b2:: with SMTP id h18mr16227182qkk.14.1562633396724; Mon, 08 Jul 2019 17:49:56 -0700 (PDT) Received: from [192.168.1.190] (pool-108-15-23-247.bltmmd.fios.verizon.net. [108.15.23.247]) by smtp.gmail.com with ESMTPSA id v28sm6219382qkj.11.2019.07.08.17.49.56 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 08 Jul 2019 17:49:56 -0700 (PDT) Subject: Re: [PATCH 3/5] grant rpm permissions to map locale_t To: "Sugar, David" , "selinux-refpolicy@vger.kernel.org" References: <20190702153014.14097-1-dsugar@tresys.com> <20190702153014.14097-4-dsugar@tresys.com> From: Chris PeBenito Message-ID: Date: Mon, 8 Jul 2019 20:39:57 -0400 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: <20190702153014.14097-4-dsugar@tresys.com> Content-Type: text/plain; charset=utf-8; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: selinux-refpolicy-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org On 7/2/19 11:30 AM, Sugar, David wrote: > type=AVC msg=audit(1560913896.408:217): avc: denied { map } for pid=1265 comm="rpm" path="/usr/lib/locale/locale-archive" dev="dm-0" ino=24721 scontext=system_u:system_r:rpm_t:s0 tcontext=system_u:object_r:locale_t:s0 tclass=file permissive=1 > > Signed-off-by: Dave Sugar > --- > policy/modules/admin/rpm.te | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/policy/modules/admin/rpm.te b/policy/modules/admin/rpm.te > index a28a24d3..7020276c 100644 > --- a/policy/modules/admin/rpm.te > +++ b/policy/modules/admin/rpm.te > @@ -207,6 +207,8 @@ libs_run_ldconfig(rpm_t, rpm_roles) > > logging_send_syslog_msg(rpm_t) > > +miscfiles_read_localization(rpm_t) > + > seutil_manage_src_policy(rpm_t) > seutil_manage_bin_policy(rpm_t) Merged. -- Chris PeBenito