From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Tue, 30 Oct 2012 14:29:30 -0400 Subject: [refpolicy] [PATCH] Arping needs setcap to cap_set_proc In-Reply-To: <1351082757-2354-1-git-send-email-dominick.grift@gmail.com> References: <1351082757-2354-1-git-send-email-dominick.grift@gmail.com> Message-ID: <50901C8A.1030407@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 10/24/12 08:45, Dominick Grift wrote: > > rhbz#869615 > > Signed-off-by: Dominick Grift > diff --git a/policy/modules/admin/netutils.te b/policy/modules/admin/netutils.te > index e0791b9..7bd6d5c 100644 > --- a/policy/modules/admin/netutils.te > +++ b/policy/modules/admin/netutils.te > @@ -35,7 +35,7 @@ > # Perform network administration operations and have raw access to the network. > allow netutils_t self:capability { net_admin net_raw setuid setgid }; > dontaudit netutils_t self:capability sys_tty_config; > -allow netutils_t self:process signal_perms; > +allow netutils_t self:process { setcap signal_perms }; > allow netutils_t self:netlink_route_socket create_netlink_socket_perms; > allow netutils_t self:packet_socket create_socket_perms; > allow netutils_t self:udp_socket create_socket_perms; Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com