From mboxrd@z Thu Jan 1 00:00:00 1970 From: cpebenito@tresys.com (Christopher J. PeBenito) Date: Tue, 20 May 2014 08:13:45 -0400 Subject: [refpolicy] [PATCH 1/1] Mark icedtea binaries as java_exec_t In-Reply-To: <1400340410-14572-1-git-send-email-sven.vermeulen@siphos.be> References: <1400340410-14572-1-git-send-email-sven.vermeulen@siphos.be> Message-ID: <537B46F9.1070200@tresys.com> To: refpolicy@oss.tresys.com List-Id: refpolicy.oss.tresys.com On 05/17/2014 11:26 AM, Sven Vermeulen wrote: > Add the icedtea location to the java file contexts so that the icedtea > java binaries are marked as java_exec_t. > > See also https://bugs.gentoo.org/show_bug.cgi?id=510364 > > Signed-off-by: Sven Vermeulen > --- > java.fc | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/java.fc b/java.fc > index e3be797..cc4f515 100644 > --- a/java.fc > +++ b/java.fc > @@ -22,6 +22,7 @@ HOME_DIR/\.java(/.*)? gen_context(system_u:object_r:java_home_t,s0) > > /usr/lib/bin/java[^/]* -- gen_context(system_u:object_r:java_exec_t,s0) > /usr/lib/eclipse/eclipse -- gen_context(system_u:object_r:java_exec_t,s0) > +/usr/lib/icedtea[67]/bin(/.*)? -- gen_context(system_u:object_r:java_exec_t,s0) > /usr/lib/jvm/java(.*/)bin(/.*)? -- gen_context(system_u:object_r:java_exec_t,s0) > /usr/lib/opera(/.*)?/opera -- gen_context(system_u:object_r:java_exec_t,s0) > /usr/lib/opera(/.*)?/works -- gen_context(system_u:object_r:java_exec_t,s0) Merged. -- Chris PeBenito Tresys Technology, LLC www.tresys.com | oss.tresys.com