From b87391cc121aafd3de4c59466696a3b63dde8964 Mon Sep 17 00:00:00 2001 From: William Pitcock Date: Tue, 8 Feb 2011 00:01:12 -0600 Subject: testing/gradm: base policy - grant reboot() capability to busybox, add /dev/hvc? to terminal device nodes --- testing/gradm/APKBUILD | 4 ++-- testing/gradm/base.policyd | 2 ++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/testing/gradm/APKBUILD b/testing/gradm/APKBUILD index 8146bc952..08dbd3af0 100644 --- a/testing/gradm/APKBUILD +++ b/testing/gradm/APKBUILD @@ -2,7 +2,7 @@ # Maintainer: William Pitcock pkgname=gradm pkgver=2.2.0 -pkgrel=4 +pkgrel=5 pkgdesc="administrative utility for grsecurity kernels" url="http://www.grsecurity.org/" arch="all" @@ -53,5 +53,5 @@ package() { md5sums="081765637a407dd7e4cd07f95413d6b8 gradm-2.2.0-201011061849.tar.gz 38ee3aef884bdcfe6a5b925760f6220b policy -1055ad6e53ab53e5d41b9eb2833bd1e7 base.policyd +1d4a2c2e522b7124ad901ae102181e72 base.policyd 2fc5d055dd43a2d9e1bed378dcab8641 grsec-rbac.initd" diff --git a/testing/gradm/base.policyd b/testing/gradm/base.policyd index 3c80101a2..cf66e7301 100644 --- a/testing/gradm/base.policyd +++ b/testing/gradm/base.policyd @@ -18,6 +18,7 @@ subject / dpo /dev/psaux rw /dev/null rw /dev/tty? rw + /dev/hvc? rw /dev/console rw /dev/tty rw /dev/pts rw @@ -118,6 +119,7 @@ subject /usr/bin/ssh subject /bin/busybox +CAP_SYS_ADMIN + +CAP_SYS_BOOT /root/.ash_history rw /dev/log rwc /var/log rwc -- cgit v1.2.3