2014-07-05 16:40:44

by Nicolas Iooss

[permalink] [raw]
Subject: [refpolicy] [PATCH] Label /usr/bin/tftpd as tftpd_exec_t

This TFTP daemon executable is provided by iputils package in Arch Linux
(https://www.archlinux.org/packages/core/x86_64/iputils/files/).
---
tftp.fc | 2 ++
1 file changed, 2 insertions(+)

diff --git a/tftp.fc b/tftp.fc
index 3dd87da..fb0b982 100644
--- a/tftp.fc
+++ b/tftp.fc
@@ -1,5 +1,7 @@
/etc/(x)?inetd\.d/tftp -- gen_context(system_u:object_r:tftpd_conf_t,s0)

+/usr/bin/tftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)
+
/usr/sbin/atftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)
/usr/sbin/in\.tftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)

--
2.0.1


2014-07-08 12:55:35

by cpebenito

[permalink] [raw]
Subject: [refpolicy] [PATCH] Label /usr/bin/tftpd as tftpd_exec_t

On 7/5/2014 12:40 PM, Nicolas Iooss wrote:
> This TFTP daemon executable is provided by iputils package in Arch Linux
> (https://www.archlinux.org/packages/core/x86_64/iputils/files/).
> ---
> tftp.fc | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/tftp.fc b/tftp.fc
> index 3dd87da..fb0b982 100644
> --- a/tftp.fc
> +++ b/tftp.fc
> @@ -1,5 +1,7 @@
> /etc/(x)?inetd\.d/tftp -- gen_context(system_u:object_r:tftpd_conf_t,s0)
>
> +/usr/bin/tftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)
> +
> /usr/sbin/atftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)
> /usr/sbin/in\.tftpd -- gen_context(system_u:object_r:tftpd_exec_t,s0)

Merged.


--
Chris PeBenito
Tresys Technology, LLC
http://www.tresys.com | oss.tresys.com