CBL-Mariner/SPECS/selinux-policy/0026-chronyd-Read-dev-urand...

28 строки
809 B
Diff

From b336b0f155c94bcc69c10d4905b1a21d5100a4e1 Mon Sep 17 00:00:00 2001
From: Chris PeBenito <Christopher.PeBenito@microsoft.com>
Date: Thu, 9 Feb 2023 19:27:14 +0000
Subject: [PATCH 26/35] chronyd: Read /dev/urandom.
Signed-off-by: Chris PeBenito <Christopher.PeBenito@microsoft.com>
---
policy/modules/services/chronyd.te | 1 +
1 file changed, 1 insertion(+)
MSFT_TAG: pending
diff --git a/policy/modules/services/chronyd.te b/policy/modules/services/chronyd.te
index 5ae7650d4..500ce6fe2 100644
--- a/policy/modules/services/chronyd.te
+++ b/policy/modules/services/chronyd.te
@@ -102,6 +102,7 @@ corenet_sendrecv_chronyd_server_packets(chronyd_t)
corenet_udp_bind_chronyd_port(chronyd_t)
dev_rw_realtime_clock(chronyd_t)
+dev_read_urand(chronyd_t)
files_read_usr_files(chronyd_t)
--
2.34.1