From mboxrd@z Thu Jan 1 00:00:00 1970 From: russell@coker.com.au (Russell Coker) Date: Wed, 3 Aug 2016 12:28:53 +1000 Subject: [refpolicy] [PATCH] ifconfig loads kernel modules In-Reply-To: References: <20160731094815.hnl6jvjkbi77vwoc@athena.coker.com.au> Message-ID: <201608031228.53604.russell@coker.com.au> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On Wed, 3 Aug 2016 09:38:02 AM Chris PeBenito wrote: > > +kernel_load_module(ifconfig_t) > > > > allow ifconfig_t self:capability { net_raw net_admin sys_admin > >sys_tty_config }; allow ifconfig_t self:process ~{ ptrace setcurrent > >setexec setfscreate setrlimit execmem execheap execstack }; allow > >ifconfig_t self:fd use; > > Is this a current denial? If so, what version of net-tools is that on? > > ifconfig_t already has kernel_request_load_module(ifconfig_t) so I'm > unclear why it would be directly loading modules itself. It's been in my tree for years. I'll remove it and see what happens. -- My Main Blog http://etbe.coker.com.au/ My Documents Blog http://doc.coker.com.au/