Bug 1100976 - [PATCH] contrib: Add KMSCon policy module
Summary: [PATCH] contrib: Add KMSCon policy module
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: selinux-policy
Version: 22
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: Lukas Vrabec
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-05-24 19:09 UTC by Lubomir Rintel
Modified: 2015-03-10 02:58 UTC (History)
4 users (show)

Fixed In Version: selinux-policy-3.13.1-116.fc22
Clone Of:
Environment:
Last Closed: 2015-03-10 02:58:48 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
[PATCH] contrib: Add KMSCon policy module (3.04 KB, patch)
2014-05-24 19:09 UTC, Lubomir Rintel
no flags Details | Diff
[PATCH] contrib: Add KMSCon policy module (3.59 KB, patch)
2014-05-24 19:49 UTC, Lubomir Rintel
no flags Details | Diff

Description Lubomir Rintel 2014-05-24 19:09:43 UTC
Created attachment 898974 [details]
[PATCH] contrib: Add KMSCon policy module

Please review & eventually apply attached change.

Thank you!

Comment 1 Lubomir Rintel 2014-05-24 19:49:37 UTC
Created attachment 898975 [details]
[PATCH] contrib: Add KMSCon policy module

Updated patch for autospawned kmscon instances. The following probably belongs to systemd.te instead:

optional_policy(`
        kmscon_systemctl(systemd_logind_t)
')

Comment 2 Miroslav Grepl 2014-05-30 15:29:05 UTC
Lukas,
could you review this policy?

Comment 3 Lubomir Rintel 2014-06-07 12:32:01 UTC
Ping?

/me *puppy face*

Comment 4 Lukas Vrabec 2014-06-08 15:13:49 UTC
Hi Lubomir, 

At first thank you for your policy, but could you check structure of our policies in git repo and reorganized your policy? It would be great!
Secondly, it's necessary to label conf (/etc/kmscon) files?

if you need any help feel free to contact me.

Comment 5 Lubomir Rintel 2014-06-12 10:16:45 UTC
(In reply to Lukas Vrabec from comment #4)
> Hi Lubomir, 
> 
> At first thank you for your policy, but could you check structure of our
> policies in git repo and reorganized your policy?

I'm not really sure what do you mean here. Comparing my policy to the existing ones I seem to be missing the section marker comments; I can fix up that one. Anything else that needs to be done?

> It would be great!
> Secondly, it's necessary to label conf (/etc/kmscon) files?

Well, there wouldn't be any real reason to let it be labelled etc_t, unless some other interface used already allows access to etc_t. I'll check that. Is that what you meant?

> 
> if you need any help feel free to contact me.

Well, it seems that I do need some :)

Comment 6 Miroslav Grepl 2014-06-12 13:03:18 UTC
If there is kmscon_admin() interface we should label it. 

Lubomir,
Lukas meant just follow 

http://oss.tresys.com/projects/refpolicy/wiki/StyleGuide

Comment 8 Lukas Vrabec 2014-06-12 13:09:07 UTC
Exactly, I want find it for you, but Miroslav overtake me.

Comment 10 Lukas Vrabec 2014-06-12 16:10:36 UTC
commit da14431fc22cd35ee14762d9cdac15955eeaf1a2
Author: Lukas Vrabec <lvrabec>
Date:   Thu Jun 12 17:11:29 2014 +0200

    re-arrange kmscon policy

commit dcce1e7a3f90f1c1edba39c6598288c3cf916f06
Author: Lubomir Rintel <lkundrak>
Date:   Sat May 24 21:06:04 2014 +0200

    contrib: Add KMSCon policy module

Thank you for patch! 
It will be included in next rawhide selinux-policy package.

Comment 11 Jaroslav Reznik 2015-03-03 17:13:40 UTC
This bug appears to have been reported against 'rawhide' during the Fedora 22 development cycle.
Changing version to '22'.

More information and reason for this action is here:
https://fedoraproject.org/wiki/Fedora_Program_Management/HouseKeeping/Fedora22

Comment 12 Fedora Update System 2015-03-06 22:08:44 UTC
selinux-policy-3.13.1-116.fc22 has been submitted as an update for Fedora 22.
https://admin.fedoraproject.org/updates/selinux-policy-3.13.1-116.fc22

Comment 13 Fedora Update System 2015-03-09 08:37:39 UTC
Package selinux-policy-3.13.1-116.fc22:
* should fix your issue,
* was pushed to the Fedora 22 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing selinux-policy-3.13.1-116.fc22'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2015-3508/selinux-policy-3.13.1-116.fc22
then log in and leave karma (feedback).

Comment 14 Fedora Update System 2015-03-10 02:58:48 UTC
selinux-policy-3.13.1-116.fc22 has been pushed to the Fedora 22 stable repository.  If problems still persist, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.