Received: by 2002:a05:6a10:16a7:0:0:0:0 with SMTP id gp39csp3574189pxb; Mon, 16 Nov 2020 19:48:28 -0800 (PST) X-Google-Smtp-Source: ABdhPJxhlDSccWqXKnBPQi0N9+EcX+AH5XZqslkojB4i4DrOqqIglIT6P6DQtbHgC+DWnlNX5z1y X-Received: by 2002:a17:906:26c7:: with SMTP id u7mr17847197ejc.96.1605584908001; Mon, 16 Nov 2020 19:48:28 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1605584907; cv=none; d=google.com; s=arc-20160816; b=SYmvdgiQTFL7qtQXqxKTc8mwmd/NHhP0POCmXT6yCttjosKbcdr69t1mB55E4kLXcv +sHSZddLUStQ2gUd+6DHw8bnSQ0nyDOkQPck+Pdu72MEHDYMw+NL8yJiw9P8cOZhocp/ LOMPvRzT9rxCoFMg6izwULSCW6c1jSn4ryaG4S7cNXx2UgjgjbCeNCfyWEmOfMf/VbKm BuB7c9Kl1G1I7mg4O6NGv6c6jBxfNx1HbQYTIpK6gttInmMZzdCixYGFIhe2hdHKanje yH5pgXGrhiL8zM3oBSt4Ewo5T02Zn/1RO2JHGqqnXoqJGOwftjPV2bmfu8PLLQdBLxhk 3bBQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from :dkim-signature; bh=nxGuoGEfRuZTa7y4H7xFf+9KzZKaSv5MT2z4ZBdDF6w=; b=GcDAYJmgoTt62xO+wxWMOwjYBHDPnsLq6JJnZNCUl3ZwtjaZOkgtNq3fzFLpuA3zzf rywfZR3Wbzf8LQT3oA5x7doz7kJPQPQnpopJEfyr7+uFVIWA7I/GCyR+DeH/lHa9oTVY I+RXT9bSaNdSEFmwGWarzTxm+d4MjHhmSwKpr0QNYf1S2ScZoWaDXb0W2VbfhLyLyon6 xdcNd1NqBsNpS1tpRQihKdPE//jhWxovm6Jevw+R6+Iy5WN+Mn9Ey28rjDpsBR3nWjn2 +Uep3116rWOlX/A3fkP9ET/75AifduhA85u/yR6yGxSm/z2r/VJPjCUj0w45kquAH9WD 1Esg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@perfinion-com.20150623.gappssmtp.com header.s=20150623 header.b=R8pb2Nsg; spf=pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id t25si22568edi.255.2020.11.16.19.48.23; Mon, 16 Nov 2020 19:48:27 -0800 (PST) Received-SPF: pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@perfinion-com.20150623.gappssmtp.com header.s=20150623 header.b=R8pb2Nsg; spf=pass (google.com: domain of selinux-refpolicy-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=selinux-refpolicy-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1727067AbgKQDrE (ORCPT + 17 others); Mon, 16 Nov 2020 22:47:04 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:55774 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726970AbgKQDrD (ORCPT ); Mon, 16 Nov 2020 22:47:03 -0500 Received: from mail-pf1-x443.google.com (mail-pf1-x443.google.com [IPv6:2607:f8b0:4864:20::443]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 9B1C7C0613CF for ; Mon, 16 Nov 2020 19:47:03 -0800 (PST) Received: by mail-pf1-x443.google.com with SMTP id 10so16218823pfp.5 for ; Mon, 16 Nov 2020 19:47:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=perfinion-com.20150623.gappssmtp.com; s=20150623; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=nxGuoGEfRuZTa7y4H7xFf+9KzZKaSv5MT2z4ZBdDF6w=; b=R8pb2Nsg9aGqBcum3p8sLTnKNKHCC/K4L3sSsGlCzUUWKyscgOh9s05/F7KLYw1I3J S8Qj3YaMUzDSJYU6bTvbKCtBYw0F9UNQC6vcU7uk0mwUZ7Yynp9aXXG3aun9yK7vXh64 gkcOswDsCENEJfY6/8kDazlrsKVYJ+Odm8P5Pkc07dBGULjSuHg/tEWF7aUre4ZfAPLP R2RYGbDWM6fWdWvxK6A+s6kHDPJXdmhubMu5J5WdfXI1Hdw6F1GubOPRH/J/ykUfdj+c kjObPqtL7vKD+qo99NnMolpRzwmZtsxkFVPOQPYJVUDNi8UX1/8Qv/Zz0L8ksdrcBiVU nRSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=nxGuoGEfRuZTa7y4H7xFf+9KzZKaSv5MT2z4ZBdDF6w=; b=HvMuQ8IdlrM2cT74U2T4f62T4KZRSmW0bVPwvkXvzACyNeOq9aNpd7Jhoo/Ew02mXq sgjO9xak9FDlDksBIoy/yDq6zTAnJlfSb4Sb1K/mmlum0Chfx+UQhcNF6mpdIAQ0Yfty ZMVaaWrIPnj4M/I83cKUG5ttgHC1FdYn9zUnJWE20TbvXGyZ1nnBacNobFz3XBJewkXV Bbs8J+LY2Tvh6+xJaAfpcvbJ2bcktA8LP24hG3hFXrMTD/jqiamt09sjvblh41Qhfj80 i6UrTTZR2wdkW/MlQEgri0t88xKbAlEbw0gCPr0E5wpuFuNaA33xApKRL5XbkjkMDywk gxfA== X-Gm-Message-State: AOAM5332oQSNrJMEacr0t7/XiAHvZOYkXJT/s0bsWQKMvWqepZqDUaPg UjmSEHQwWduroj3woA7PzN9hiWpLHJt2vFFY X-Received: by 2002:aa7:9e88:0:b029:18b:c1b7:a8cd with SMTP id p8-20020aa79e880000b029018bc1b7a8cdmr16986184pfq.21.1605584822871; Mon, 16 Nov 2020 19:47:02 -0800 (PST) Received: from localhost (115.42.24.136.in-addr.arpa. [136.24.42.115]) by smtp.gmail.com with ESMTPSA id j26sm1512945pgn.27.2020.11.16.19.47.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 16 Nov 2020 19:47:02 -0800 (PST) From: Jason Zaman To: selinux-refpolicy@vger.kernel.org Cc: Jason Zaman Subject: [PATCH 7/8] init: upstream fcontexts from gentoo policy Date: Mon, 16 Nov 2020 19:46:27 -0800 Message-Id: <20201117034628.2461-7-jason@perfinion.com> X-Mailer: git-send-email 2.26.2 In-Reply-To: <20201117034628.2461-1-jason@perfinion.com> References: <20201117034628.2461-1-jason@perfinion.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Precedence: bulk List-ID: X-Mailing-List: selinux-refpolicy@vger.kernel.org Signed-off-by: Jason Zaman --- policy/modules/system/init.fc | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/policy/modules/system/init.fc b/policy/modules/system/init.fc index f1e6a61d0..63cf195e6 100644 --- a/policy/modules/system/init.fc +++ b/policy/modules/system/init.fc @@ -44,8 +44,11 @@ ifdef(`distro_gentoo',` /usr/sbin/upstart -- gen_context(system_u:object_r:init_exec_t,s0) ifdef(`distro_gentoo', ` +/usr/lib/rc/cache(/.*)? gen_context(system_u:object_r:initrc_state_t,s0) +/usr/lib/rc/console(/.*)? gen_context(system_u:object_r:initrc_state_t,s0) /usr/lib/rc/init\.d(/.*)? gen_context(system_u:object_r:initrc_state_t,s0) -/usr/sbin/rc -- gen_context(system_u:object_r:rc_exec_t,s0) +/usr/sbin/rc -- gen_context(system_u:object_r:rc_exec_t,s0) +/usr/sbin/openrc -- gen_context(system_u:object_r:rc_exec_t,s0) /usr/sbin/openrc-init -- gen_context(system_u:object_r:init_exec_t,s0) /usr/sbin/openrc-shutdown -- gen_context(system_u:object_r:init_exec_t,s0) ') @@ -79,6 +82,9 @@ ifdef(`distro_debian',` ifdef(`distro_gentoo', ` /var/lib/init\.d(/.*)? gen_context(system_u:object_r:initrc_state_t,s0) +/var/lib/ip6?tables(/.*)? gen_context(system_u:object_r:initrc_tmp_t,s0) + +/run/openrc(/.*)? gen_context(system_u:object_r:initrc_state_t,s0) /run/svscan\.pid -- gen_context(system_u:object_r:initrc_runtime_t,s0) ') -- 2.26.2