2017-11-27 14:23:08

by Daniel Jurgens

[permalink] [raw]
Subject: [refpolicy] [PATCH 1/1] networkmanager: Grant access to unlabeled PKeys

From: Daniel Jurgens <[email protected]>

For controlling IPoIB VLANs

Reported-by: Honggang LI <[email protected]>
Signed-off-by: Daniel Jurgens <[email protected]>
Tested-by: Honggang LI <[email protected]>
---
networkmanager.te | 2 ++
1 files changed, 2 insertions(+), 0 deletions(-)

diff --git a/networkmanager.te b/networkmanager.te
index 76d0106..5e881f4 100644
--- a/networkmanager.te
+++ b/networkmanager.te
@@ -184,6 +184,8 @@ userdom_write_user_tmp_sockets(NetworkManager_t)
userdom_dontaudit_use_unpriv_user_fds(NetworkManager_t)
userdom_dontaudit_use_user_ttys(NetworkManager_t)

+corenet_ib_access_unlabeled_pkeys(NetworkManager_t)
+
optional_policy(`
avahi_domtrans(NetworkManager_t)
avahi_kill(NetworkManager_t)
--
1.7.1


2017-11-29 01:37:16

by Chris PeBenito

[permalink] [raw]
Subject: [refpolicy] [PATCH 1/1] networkmanager: Grant access to unlabeled PKeys

On 11/27/2017 09:23 AM, Dan Jurgens wrote:
> From: Daniel Jurgens <[email protected]>
>
> For controlling IPoIB VLANs
>
> Reported-by: Honggang LI <[email protected]>
> Signed-off-by: Daniel Jurgens <[email protected]>
> Tested-by: Honggang LI <[email protected]>
> ---
> networkmanager.te | 2 ++
> 1 files changed, 2 insertions(+), 0 deletions(-)
>
> diff --git a/networkmanager.te b/networkmanager.te
> index 76d0106..5e881f4 100644
> --- a/networkmanager.te
> +++ b/networkmanager.te
> @@ -184,6 +184,8 @@ userdom_write_user_tmp_sockets(NetworkManager_t)
> userdom_dontaudit_use_unpriv_user_fds(NetworkManager_t)
> userdom_dontaudit_use_user_ttys(NetworkManager_t)
>
> +corenet_ib_access_unlabeled_pkeys(NetworkManager_t)
> +
> optional_policy(`
> avahi_domtrans(NetworkManager_t)
> avahi_kill(NetworkManager_t)

Merged.

--
Chris PeBenito