From: sven.vermeulen@siphos.be (Sven Vermeulen) Date: Wed, 29 Aug 2012 21:28:42 +0200 Subject: [refpolicy] [PATCH v1 1/5] Puppet uses mount output for verification In-Reply-To: <1346268526-22260-1-git-send-email-sven.vermeulen@siphos.be> References: <1346268526-22260-1-git-send-email-sven.vermeulen@siphos.be> Message-ID: <1346268526-22260-2-git-send-email-sven.vermeulen@siphos.be> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com Puppet calls mount to obtain the list of mounted file systems, redirecting its output to a temporary file (labeled puppet_tmp_t). This allows the mount domain to write to this resource. Signed-off-by: Sven Vermeulen --- policy/modules/system/mount.te | 4 ++++ 1 files changed, 4 insertions(+), 0 deletions(-) diff --git a/policy/modules/system/mount.te b/policy/modules/system/mount.te index 63931f6..4175ff7 100644 --- a/policy/modules/system/mount.te +++ b/policy/modules/system/mount.te @@ -193,6 +193,10 @@ optional_policy(` ') ') +optional_policy(` + puppet_rw_tmp(mount_t) +') + # for kernel package installation optional_policy(` rpm_rw_pipes(mount_t) -- 1.7.8.6