[selinux-policy: 1809/3172] trunk: Patch to add missing requirements in userdomain interfaces from Shintaro Fujiwara.
Daniel J Walsh
dwalsh at fedoraproject.org
Thu Oct 7 21:41:29 UTC 2010
commit 6f49b490b834bb3a3168db28ff662fdb9ddb7f27
Author: Chris PeBenito <cpebenito at tresys.com>
Date: Mon Sep 17 18:04:35 2007 +0000
trunk: Patch to add missing requirements in userdomain interfaces from Shintaro Fujiwara.
Changelog | 2 ++
policy/modules/system/userdomain.if | 8 ++++----
policy/modules/system/userdomain.te | 2 +-
3 files changed, 7 insertions(+), 5 deletions(-)
---
diff --git a/Changelog b/Changelog
index 5f55572..5775670 100644
--- a/Changelog
+++ b/Changelog
@@ -1,3 +1,5 @@
+- Patch to add missing requirements in userdomain interfaces from Shintaro
+ Fujiwara.
- Add tcpd_wrapped_domain() for services that use tcp wrappers.
- Update MLS constraints from LSPP evaluated policy.
- Allow initrc_t file descriptors to be inherited regardless of MLS level.
diff --git a/policy/modules/system/userdomain.if b/policy/modules/system/userdomain.if
index 2248ca7..f01c490 100644
--- a/policy/modules/system/userdomain.if
+++ b/policy/modules/system/userdomain.if
@@ -5076,7 +5076,7 @@ interface(`userdom_manage_generic_user_home_dirs',`
#
interface(`userdom_manage_generic_user_home_content_dirs',`
gen_require(`
- type user_home_t;
+ type user_home_dir_t, user_home_t;
')
files_search_home($1)
@@ -5194,7 +5194,7 @@ interface(`userdom_dontaudit_relabel_generic_user_home_content_files',`
#
interface(`userdom_manage_generic_user_home_content_symlinks',`
gen_require(`
- type user_home_t;
+ type user_home_dir_t, user_home_t;
')
files_search_home($1)
@@ -5214,7 +5214,7 @@ interface(`userdom_manage_generic_user_home_content_symlinks',`
#
interface(`userdom_manage_generic_user_home_content_pipes',`
gen_require(`
- type user_home_t;
+ type user_home_dir_t, user_home_t;
')
files_search_home($1)
@@ -5234,7 +5234,7 @@ interface(`userdom_manage_generic_user_home_content_pipes',`
#
interface(`userdom_manage_generic_user_home_content_sockets',`
gen_require(`
- type user_home_t;
+ type user_home_dir_t, user_home_t;
')
files_search_home($1)
diff --git a/policy/modules/system/userdomain.te b/policy/modules/system/userdomain.te
index 6928566..b6da415 100644
--- a/policy/modules/system/userdomain.te
+++ b/policy/modules/system/userdomain.te
@@ -1,5 +1,5 @@
-policy_module(userdomain,2.3.1)
+policy_module(userdomain,2.3.2)
gen_require(`
role sysadm_r, staff_r, user_r;
More information about the scm-commits
mailing list