From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Sat, 24 Sep 2011 15:56:58 +0200 Subject: [refpolicy] [PATCH 1/1] Mount output should be writeable to puppet_tmp_t Message-ID: <20110924135657.GA8045@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com When using puppet to configure systems, the puppet system runs the mount command and captures its output in a temporary file in /tmp (which is labeled puppet_tmp_t). Signed-off-by: Sven Vermeulen --- policy/modules/system/mount.te | 4 ++++ 1 files changed, 4 insertions(+), 0 deletions(-) diff --git a/policy/modules/system/mount.te b/policy/modules/system/mount.te index 1284081..ca9cdc0 100644 --- a/policy/modules/system/mount.te +++ b/policy/modules/system/mount.te @@ -191,6 +191,10 @@ optional_policy(` ') ') +optional_policy(` + puppet_rw_tmp(mount_t) +') + # for kernel package installation optional_policy(` rpm_rw_pipes(mount_t) -- 1.7.3.4