Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 431654 - Allow sysadm the necessary rights for named init scripts
Summary: Allow sysadm the necessary rights for named init scripts
Status: VERIFIED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: SELinux (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: SE Linux Bugs
URL:
Whiteboard: sec-policy
Keywords:
Depends on:
Blocks: 424173
  Show dependency tree
 
Reported: 2012-08-16 17:02 UTC by Sven Vermeulen (RETIRED)
Modified: 2012-10-04 18:34 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sven Vermeulen (RETIRED) gentoo-dev 2012-08-16 17:02:40 UTC
Since 20120725-r2 and higher, named init scripts are now almost mandatory to use. If an init script is labeled <domain>_initrc_exec_t, then this is a named init script. This bug will be used to track the various domains for which sysadm_t doesn't have the proper rights to work with the named init script yet.

A workaround is to label the file "initrc_exec_t", but this is not in line with the purpose of the named init scripts.

Reproducible: Always
Comment 1 Sven Vermeulen (RETIRED) gentoo-dev 2012-08-16 17:03:19 UTC
Domains:

- postgresql
- asterisk
Comment 2 Sven Vermeulen (RETIRED) gentoo-dev 2012-08-16 18:50:36 UTC
More domains:

- openvpn
- ntp
- bind
Comment 3 Sven Vermeulen (RETIRED) gentoo-dev 2012-08-25 17:15:08 UTC
Domains:

- consolekit (/run/ConsoleKit)
Comment 4 Sven Vermeulen (RETIRED) gentoo-dev 2012-09-08 18:16:38 UTC
rev 5 is in hardened-dev overlay

(for newly found domains needing this, please open a new bugreport)
Comment 5 Sven Vermeulen (RETIRED) gentoo-dev 2012-09-22 11:31:06 UTC
In main tree, ~arch'ed (rev 5)
Comment 6 Sven Vermeulen (RETIRED) gentoo-dev 2012-10-04 18:34:38 UTC
stabilized