From Debian package 0.0.20080702-12 Use audioentropy policy for randomsound Module renaming (from audio_entropy to audioentropy) merged upstream in r2892 Module was renamed upstream to entropyd in ee4bdf29 (2011-07-25) Index: policy/modules/services/entropyd.fc =================================================================== --- policy/modules/services/entropyd.fc.orig +++ policy/modules/services/entropyd.fc @@ -1,6 +1,7 @@ # # /usr # +/usr/sbin/randomsound -- gen_context(system_u:object_r:entropyd_exec_t,s0) /usr/sbin/audio-entropyd -- gen_context(system_u:object_r:entropyd_exec_t,s0) /usr/sbin/haveged -- gen_context(system_u:object_r:entropyd_exec_t,s0) Index: policy/modules/services/entropyd.te =================================================================== --- policy/modules/services/entropyd.te.orig +++ policy/modules/services/entropyd.te @@ -26,12 +26,21 @@ allow entropyd_t self:capability { dac_override ipc_lock sys_admin }; dontaudit entropyd_t self:capability sys_tty_config; -allow entropyd_t self:process signal_perms; +allow entropyd_t self:process { signal_perms setpgid }; allow entropyd_t self:unix_dgram_socket create_socket_perms; +allow entropyd_t self:sem create_sem_perms; +allow entropyd_t self:shm create_shm_perms; +type entropyd_tmpfs_t; +files_type(entropyd_tmpfs_t) +manage_files_pattern(entropyd_t,entropyd_tmpfs_t,entropyd_tmpfs_t) +fs_tmpfs_filetrans(entropyd_t,entropyd_tmpfs_t, file) manage_files_pattern(entropyd_t, entropyd_var_run_t, entropyd_var_run_t) files_pid_filetrans(entropyd_t, entropyd_var_run_t, file) +corecmd_search_bin(entropyd_t) +corecmd_exec_bin(entropyd_t) + kernel_rw_kernel_sysctl(entropyd_t) kernel_list_proc(entropyd_t) kernel_read_proc_symlinks(entropyd_t)