commit:     99b40156a93dcd1147049daca610b53d20eaa4b7
Author:     Jason Zaman <jason <AT> perfinion <DOT> com>
AuthorDate: Sat Dec 20 13:46:45 2014 +0000
Commit:     Jason Zaman <gentoo <AT> perfinion <DOT> com>
CommitDate: Sat Dec 20 13:46:45 2014 +0000
URL:        
http://sources.gentoo.org/gitweb/?p=proj/hardened-refpolicy.git;a=commit;h=99b40156

salt: allow salt minion to ssh_manage_home_files

also dac_override and dac_read_search since some home dirs are not
world readable.

---
 policy/modules/contrib/salt.te | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/policy/modules/contrib/salt.te b/policy/modules/contrib/salt.te
index 279edfb..024a165 100644
--- a/policy/modules/contrib/salt.te
+++ b/policy/modules/contrib/salt.te
@@ -198,7 +198,7 @@ tunable_policy(`salt_master_read_nfs',`
 # salt_minion_t policy
 #
 
-allow salt_minion_t self:capability { fsetid chown net_admin sys_admin 
sys_tty_config };
+allow salt_minion_t self:capability { fsetid chown dac_override 
dac_read_search net_admin sys_admin sys_tty_config };
 allow salt_minion_t self:capability2 block_suspend;
 allow salt_minion_t self:process { signal signull };
 allow salt_minion_t self:tcp_socket create_stream_socket_perms;
@@ -294,6 +294,10 @@ optional_policy(`
 ')
 
 optional_policy(`
+       ssh_manage_home_files(salt_minion_t)
+')
+
+optional_policy(`
        mount_domtrans(salt_minion_t)
 ')
 

Reply via email to